Configuring IBM Disconnected Log Collector to communicate with QRadar
To forward events to IBM QRadar, you must edit the configuration file on your Disconnected Log Collector (DLC) console.
Before you begin
IBM® Disconnected Log Collector must be configured to collect events and forward them to QRadar. For more information, see the IBM Disconnected Log Collector documentation (https://www.ibm.com/support/knowledgecenter/SS42VS_SHR/com.ibm.dlc.doc/c_dlc_overview.html).
About this task
IBM Disconnected Log Collector 1.5 sends some metric events to QRadar to monitor some key statistics from your Disconnected Log Collector. Disconnected Log Collector sends 3 different metric events once every minute.
The following table describes the 3 metric event types that are sent to QRadar.
| Component name | Metric ID | Description |
|---|---|---|
| EventProcessingFilterQueue | SpillFilesCount | If the incoming event rate exceeds the capacity to process the events, the count increases. |
| ecs-dlc_dlc_TCP_TO_QRADAR | SpillFilesCount | If DLC is disconnected, or the incoming event rate exceeds outgoing EPS setting in DLC, the count increases. |
| Source Monitor | EventRate | The current eps rate that is collected by DLC. |