IBM QRadar

 View Only
Expand all | Collapse all

Log sources Error: Troubleshooting

  • 1.  Log sources Error: Troubleshooting

    Posted Thu July 25, 2024 07:42 AM

    Hey all, I currently have some log sources (mainly WinCollect types) in Error in my qradar deployement, but what I don't understand is why I'm receiving the system heartbeats events and not the receiving log events. Does anyone have an idea what's the problem? 

    Thanks in advance for your feedbacks.



    ------------------------------
    Essotassim LANGUIE
    ------------------------------


  • 2.  RE: Log sources Error: Troubleshooting

    IBM Champion
    Posted Fri July 26, 2024 02:46 AM

    Hi Essotassim,

    wincollect has some dependencies to check. Your description has no details about which versions and configurations you're running. Depending on this, different ports and options come into play... without details difficult to assess. But here is a helpful link to start, maybe you are already aware of:

    https://www.ibm.com/community/101/qradar/wincollect/

    This will support you with many details to check.

    Regards,

    Ralph



    ------------------------------
    Ralph Belfiore
    Managing Consultant | Senior SIEM Expert
    connecT SYSTEMHAUS AG
    Siegen
    +491726365525
    ------------------------------