Getting Data In

Is it possible to forward logs from QRadar to Splunk and still be able to correlate the data for each device in Splunk?

mlmcadams
Engager

We have many devices sending logs to QRadar. Is it possible to forward logs from QRadar to Splunk and still be able to correlate the data for each device in Splunk?

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

It all depends on how Qradar sends the logs. If you can get syslog out, then collect it via syslog in Splunk and extract the host name from the log file. That should be easy for Splunk to do. We do it the other way, Splunk -> Qradar using _SYSLOG_ROUTING. Qradar just can't parse the incoming data correctly for some reason. You'd think since it is regex based it would just work.......

0 Karma

Nilkanth
New Member

hi can you explain why Qradar just can't parse the incoming data correctly for some reason
because we are also facing same issue.We are using splunk as log collector only and via heavy forwarder we are receiving logs on Qroc (Qradra cloud version) with one LB in between.now the problem is none of the data is getting parsed at Qroc end.
for all logs we are getting only Datagateway IP as device address.
so my questions is does Splunk support as kind of integration.does splunk modify original log format.is there any way we can solve this mess

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...