Lastline Enterprise
The IBM QRadar DSM for Lastline Enterprise receives anti-malware events from Lastline Enterprise systems.
The following table identifies the specifications for the Lastline Enterprise DSM:
| Specification | Value |
|---|---|
| Manufacturer | Lastline |
| DSM name | Lastline Enterprise |
| RPM file name | DSM-LastlineEnterprise-Qradar_version-build_number.noarch.rpm |
| Supported versions | 6.0 |
| Protocol | LEEF |
| Recorded event types | Anti-malware |
| Automatically discovered? | Yes |
| Includes identity? | No |
| Includes custom properties? | No |
| More information | Lastline website (http://www.lastline.com) |
To send Lastline Enterprise events to QRadar, complete
the following steps:
- If automatic updates are not enabled, download and install the most recent
version of the following RPMs from the IBM® Support Website onto your QRadar
Console:
- DSMCommon RPM
- Lastline Enterprise DSM RPM
- Configure your Lastline Enterprise device to send syslog events to QRadar.
- If QRadar
does not automatically detect the log source, add a Lastline Enterprise log
source on the QRadar
Console. The following table describes the parameters that require specific
values that are required for Lastline Enterprise event collection:
Table 2. Lastline Enterprise log source parameters Parameter Value Log Source type Lastline Enterprise Protocol Configuration Syslog