To stay updated on your favorite discussions, please create an account or log in. Then, click the Bookmark icon to subscribe and receive notifications.

alerts forwarding to IBM Qradar SIEM are not parsing

Shekhar
Shekhar W/ Alumni Posts: 5 Security Scout

Hi

I am forwaring F secure PM alerts and notifications to IBM Qradar SIEM over syslog but events which are recievied to IBM Qradar are unparsed. Kindly let me know whether we can resolve this from F secure side or Can I check with IBM support.

 

Thanks

Comments

  • Shekhar
    Shekhar W/ Alumni Posts: 5 Security Scout

    yes we are able to see the logs at SIEM we will check wih IBM

  • Tomasz_009
    Tomasz_009 W/ Alumni Posts: 1 Security Scout

    Hello,

     

    We also sending event from F-Secure to QRadar. Event aren't parsing so you need create own DSM for this events - if I good know, IBM don't have native DSM for F-Secure events.

This discussion has been closed.