cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
177
Views
0
Helpful
2
Replies

Recommended logs that should be sent to IBM QRADAR SIEM from ESA

Vijay.Reddy
Level 1
Level 1

Any thoughts on recommended logs that should be sent to QRADAR SIEM ? 

 

what subscriptions should be configured ? 

2 Replies 2

I would create a Single Line Log subscription add everything and send that...

The go to the SEIM and write a parser for it.

What's your remit and what's your budget allowance
We log every log subscription ( unless its an unused feature ) and also collect data via SSH HTTPs connections
Ran out of budget on the LDAP logs - and really needed them the other day to analyse a strange stall in rewrite queries but not accept queries

Single Log Line is OK on a basic level - and should allow filtering out log lines from other subscriptions
Better off with a custom log consolidator + generate other metrics + log what you don't purposely filter out.

Depends on what you are analysing / detecting.