A logging pool is used to define a pool of servers that receive syslog events. The pool
contains the IP address, port, and a node name that you provide.
Procedure
-
From the navigation menu, select .
-
Click Create.
-
In the Name field, type a name for the logging
pool.
For example, Logging_Pool.
-
From the Health Monitor field, in the Available
list, select TCP and click <<.
This clicking action moves the TCP option from the Available list to the Selected list.
-
In the Resource pane, from the Node Name list,
select Logging_Node or the name you defined in Configuring a logging pool.
-
In the Address field, type the IP address for the QRadar
Console or Event Collector.
-
In the Service Port field, type 514.
-
Click Add.
-
Click Finish.