Getting Data In

Is it possible to forward logs from QRadar to Splunk and still be able to correlate the data for each device in Splunk?

mlmcadams
Engager

We have many devices sending logs to QRadar. Is it possible to forward logs from QRadar to Splunk and still be able to correlate the data for each device in Splunk?

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

It all depends on how Qradar sends the logs. If you can get syslog out, then collect it via syslog in Splunk and extract the host name from the log file. That should be easy for Splunk to do. We do it the other way, Splunk -> Qradar using _SYSLOG_ROUTING. Qradar just can't parse the incoming data correctly for some reason. You'd think since it is regex based it would just work.......

0 Karma

Nilkanth
New Member

hi can you explain why Qradar just can't parse the incoming data correctly for some reason
because we are also facing same issue.We are using splunk as log collector only and via heavy forwarder we are receiving logs on Qroc (Qradra cloud version) with one LB in between.now the problem is none of the data is getting parsed at Qroc end.
for all logs we are getting only Datagateway IP as device address.
so my questions is does Splunk support as kind of integration.does splunk modify original log format.is there any way we can solve this mess

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...