Microsoft Azure Local and Microsoft Azure Local Disconnected

IBM QRadar supports ingesting events from Microsoft Azure Local and Microsoft Azure Local Disconnected environments, including security events, audit logs, and security alerts.

These events are primarily forwarded in Syslog format, which allows QRadar to ingest them by using the standard Syslog protocol.

To integrate Microsoft Azure Local and Microsoft Azure Local Disconnected with QRadar, complete the following steps:

  1. Configure Syslog forwarding on Microsoft Azure Local and Microsoft Azure Local Disconnected environments. QRadar supports Syslog as the ingestion mechanism for these events. For more information, see Manage syslog forwarding in the Microsoft documentation.
  2. Create a Custom Log Source Type in QRadar to parse the incoming events. For more information, see Creating a custom log source type to parse events.
  3. Create a Universal DSM by using the DSM Editor to extract the required fields from the incoming Syslog events. Complete the following steps:
    1. Log in to the QRadar Console with administrator credentials.
    2. From the QRadar Console, click the Admin tab.
    3. In the Data Sources section, click DSM Editor.
      Figure 1. DSM Editor
      DSM Editor
    4. Create a log source type or select an existing log source type. Select the Universal DSM in the search bar and click Select.
      Figure 2. Select Universal DSM
      Select Universal DSM
    5. Click the pencil icon and enter your payload in the text area.
      Figure 3. Add payload
      Add payload
      Figure 4. Add payload in the text area
      Add payload in the text area
    6. Use regular expressions to parse the required fields from the payload, such as event ID, event category, and username.
      Figure 5. Parse payload
      Parse payload
    7. After you parse all the required values, click the Configuration tab and enable the following properties:
      • Enable Property Autodetection
      • Enable Log Source Autodetection
      Figure 6. Enable Property Autodetection and Enable Log Source Autodetection
      Enable Property Autodetection and Enable Log Source Autodetection
    8. Click Save. Events are automatically detected for the Universal DSM.
    For more information, see DSM Editor overview.
  4. Create event mappings and event categories to normalize the events within QRadar. For more information, see Creating an event map categorization.

QRadar can now ingest, parse, normalize, and categorize Microsoft Azure Local and Microsoft Azure Local Disconnected security events for monitoring and correlation purposes.