<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I am using third party forwarding from Splunk to QRadar but the events are not being displayed correctly. How can I correct this? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/I-am-using-third-party-forwarding-from-Splunk-to-QRadar-but-the/m-p/70934#M14433</link>
    <description>&lt;P&gt;Here is a document regarding the Qradar configuration from IBM's site:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www-01.ibm.com/support/knowledgecenter/SS42VS_7.2.5/com.ibm.dsm.doc/t_DSM_guide_Splunk_logsource.html%23t_dsm_guide_splunk_logsource"&gt;http://www-01.ibm.com/support/knowledgecenter/SS42VS_7.2.5/com.ibm.dsm.doc/t_DSM_guide_Splunk_logsource.html%23t_dsm_guide_splunk_logsource&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 16 Feb 2016 20:24:50 GMT</pubDate>
    <dc:creator>jcrabb_splunk</dc:creator>
    <dc:date>2016-02-16T20:24:50Z</dc:date>
    <item>
      <title>I am using third party forwarding from Splunk to QRadar but the events are not being displayed correctly. How can I correct this?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-am-using-third-party-forwarding-from-Splunk-to-QRadar-but-the/m-p/70928#M14427</link>
      <description>&lt;P&gt;My Splunk setup is a UF sending to an indexer. That indexer is then forwarding everything to QRadar. When I look at the events in QRadar, they are mangled. What I see is each key value pair is its' own event instead of all of the pairs being part of a single event. &lt;/P&gt;

&lt;P&gt;Example: &lt;/P&gt;

&lt;P&gt;Real event looks like:&lt;/P&gt;

&lt;P&gt;09-Sep-2012 14:48:29  AgentDevice=WindowsLog AgentLogFile=Security&lt;/P&gt;

&lt;P&gt;But it's getting broke into separate events like this:&lt;/P&gt;

&lt;P&gt;Event 1-&lt;BR /&gt;
09-Sep-2012 14:48:29&lt;/P&gt;

&lt;P&gt;Event 2-&lt;BR /&gt;
AgentDevice=WindowsLogs&lt;/P&gt;

&lt;P&gt;Event 3-&lt;BR /&gt;
AgentLogfile=Security&lt;/P&gt;

&lt;P&gt;Why?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2012 22:18:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-am-using-third-party-forwarding-from-Splunk-to-QRadar-but-the/m-p/70928#M14427</guid>
      <dc:creator>DerekB</dc:creator>
      <dc:date>2012-09-25T22:18:22Z</dc:date>
    </item>
    <item>
      <title>Re: I am using third party forwarding from Splunk to QRadar but the events are not being displayed correctly. How can I correct this?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-am-using-third-party-forwarding-from-Splunk-to-QRadar-but-the/m-p/70929#M14428</link>
      <description>&lt;P&gt;We've seen this before, and what we noticed was that when we looked at the single line event data the instance was generating, it was all showing up in QRadar normally.  The problem turned out to be that QRadar doesn't understand how to deal with multiline events, so each line is handled as an individual event. We confirmed the behavior with the vendor, presently it is a limitation of the product. &lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2012 22:23:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-am-using-third-party-forwarding-from-Splunk-to-QRadar-but-the/m-p/70929#M14428</guid>
      <dc:creator>jbsplunk</dc:creator>
      <dc:date>2012-09-25T22:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: I am using third party forwarding from Splunk to QRadar but the events are not being displayed correctly. How can I correct this?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-am-using-third-party-forwarding-from-Splunk-to-QRadar-but-the/m-p/70930#M14429</link>
      <description>&lt;P&gt;Isn't this a QRadar issue rather than a Splunk issue?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2012 22:25:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-am-using-third-party-forwarding-from-Splunk-to-QRadar-but-the/m-p/70930#M14429</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-09-25T22:25:48Z</dc:date>
    </item>
    <item>
      <title>Re: I am using third party forwarding from Splunk to QRadar but the events are not being displayed correctly. How can I correct this?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-am-using-third-party-forwarding-from-Splunk-to-QRadar-but-the/m-p/70931#M14430</link>
      <description>&lt;P&gt;Yes, but it's good to have documented.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2012 22:30:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-am-using-third-party-forwarding-from-Splunk-to-QRadar-but-the/m-p/70931#M14430</guid>
      <dc:creator>jbsplunk</dc:creator>
      <dc:date>2012-09-25T22:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: I am using third party forwarding from Splunk to QRadar but the events are not being displayed correctly. How can I correct this?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-am-using-third-party-forwarding-from-Splunk-to-QRadar-but-the/m-p/70932#M14431</link>
      <description>&lt;P&gt;Is this something that has been corrected since 2012? We are looking to do the same thing here with SystemOut and http access logs from Splunk indexer to QRadar.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2014 13:32:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-am-using-third-party-forwarding-from-Splunk-to-QRadar-but-the/m-p/70932#M14431</guid>
      <dc:creator>buttona</dc:creator>
      <dc:date>2014-10-30T13:32:05Z</dc:date>
    </item>
    <item>
      <title>Re: I am using third party forwarding from Splunk to QRadar but the events are not being displayed correctly. How can I correct this?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-am-using-third-party-forwarding-from-Splunk-to-QRadar-but-the/m-p/70933#M14432</link>
      <description>&lt;P&gt;You can upgrade to a newer version of Qradar which adds Splunk as a source and fixes this issue&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2014 14:47:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-am-using-third-party-forwarding-from-Splunk-to-QRadar-but-the/m-p/70933#M14432</guid>
      <dc:creator>jmann2118</dc:creator>
      <dc:date>2014-10-30T14:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: I am using third party forwarding from Splunk to QRadar but the events are not being displayed correctly. How can I correct this?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-am-using-third-party-forwarding-from-Splunk-to-QRadar-but-the/m-p/70934#M14433</link>
      <description>&lt;P&gt;Here is a document regarding the Qradar configuration from IBM's site:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www-01.ibm.com/support/knowledgecenter/SS42VS_7.2.5/com.ibm.dsm.doc/t_DSM_guide_Splunk_logsource.html%23t_dsm_guide_splunk_logsource"&gt;http://www-01.ibm.com/support/knowledgecenter/SS42VS_7.2.5/com.ibm.dsm.doc/t_DSM_guide_Splunk_logsource.html%23t_dsm_guide_splunk_logsource&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2016 20:24:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-am-using-third-party-forwarding-from-Splunk-to-QRadar-but-the/m-p/70934#M14433</guid>
      <dc:creator>jcrabb_splunk</dc:creator>
      <dc:date>2016-02-16T20:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: I am using third party forwarding from Splunk to QRadar but the events are not being displayed correctly. How can I correct this?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-am-using-third-party-forwarding-from-Splunk-to-QRadar-but-the/m-p/70935#M14434</link>
      <description>&lt;P&gt;DerekB,&lt;BR /&gt;
Can you share Splunk configuration details for Forwarding all data from Splunk Indexer to QRadar ?&lt;BR /&gt;
Will, having just the outputs.conf work?&lt;BR /&gt;
outputs.conf&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
defaultGroup = SIEM_12345&lt;BR /&gt;
indexAndForward = true&lt;BR /&gt;
disabled = false&lt;/P&gt;

&lt;P&gt;[tcpout:SIEM_12345]&lt;BR /&gt;
server = SIEM_IP:12345&lt;BR /&gt;
compressed = true&lt;BR /&gt;
sendCookedData = true&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:18:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-am-using-third-party-forwarding-from-Splunk-to-QRadar-but-the/m-p/70935#M14434</guid>
      <dc:creator>rajanala</dc:creator>
      <dc:date>2020-09-29T09:18:33Z</dc:date>
    </item>
  </channel>
</rss>

