Getting Data In

Is it possible to forward logs from QRadar to Splunk and still be able to correlate the data for each device in Splunk?

mlmcadams
Engager

We have many devices sending logs to QRadar. Is it possible to forward logs from QRadar to Splunk and still be able to correlate the data for each device in Splunk?

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

It all depends on how Qradar sends the logs. If you can get syslog out, then collect it via syslog in Splunk and extract the host name from the log file. That should be easy for Splunk to do. We do it the other way, Splunk -> Qradar using _SYSLOG_ROUTING. Qradar just can't parse the incoming data correctly for some reason. You'd think since it is regex based it would just work.......

0 Karma

Nilkanth
New Member

hi can you explain why Qradar just can't parse the incoming data correctly for some reason
because we are also facing same issue.We are using splunk as log collector only and via heavy forwarder we are receiving logs on Qroc (Qradra cloud version) with one LB in between.now the problem is none of the data is getting parsed at Qroc end.
for all logs we are getting only Datagateway IP as device address.
so my questions is does Splunk support as kind of integration.does splunk modify original log format.is there any way we can solve this mess

0 Karma
Get Updates on the Splunk Community!

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

Unlock Instant Security Insights from Amazon S3 with Splunk Cloud — Try Federated ...

Availability: Must be on Splunk Cloud Platform version 10.1.2507.x to view the free trial banner. If you are ...