Configuring BlueCat Adonis

You can configure your BlueCat Adonis appliance to forward DNS and DHCP events to IBM QRadar SIEM.

Procedure

  1. Using SSH, log in to your BlueCat Adonis appliance.
  2. On the command-line interface type the following command to start the syslog configuration script:

    /usr/local/bluecat/QRadar/setup-QRadar.sh

  3. Type the IP address of your QRadar Console or Event Collector.
  4. Type yes or no to confirm the IP address.

    The configuration is complete when a success message is displayed.

    The log source is added to QRadar as BlueCat Networks Adonis syslog events are automatically discovered. Events that are forwarded to QRadar are displayed on the Log Activity tab. If the events are not automatically discovered, you can manually configure a log source.