/
QRadar Configuration
QRadar Configuration
Log Source for CDC Events
QRadar will try to create a Log Source automatically once it begins receiving CDC events, but you may need to create one manually. To do so, perform the following.
In QRadar, navigate to Admin → Log Sources.
Click + New Log Source.
Select Single Log Source.
Search for the Infoblox CDC log source type.
Search for the Syslog protocol.
Configure Log Source Parameters:
Set the Name to Infoblox-CDC.
NOTE: If you change this name, you will also need to change Logsource parameter in the Pulse dashboards to match.Set the Extension to InfobloxCDCCustom_ext.
Set Store Event Payloads to True.
Set Coalescing Events to Disabled.
Set other settings as desired.
Set a relevant Log Source Identifier.
Set the Incoming Payload Encoding to UTF-8.
Click Finish.
Related content
Create Log Source to collect LEEF data
Create Log Source to collect LEEF data
More like this
Ingestion and Parsing
Ingestion and Parsing
More like this
Setting up IBM QRadar
Setting up IBM QRadar
More like this
CSP Configuration
CSP Configuration
More like this