The Tripwire DSM accepts resource additions, removal, and modification events by using
syslog.
Procedure
-
Log in to the Tripwire interface.
-
On the left navigation, click Actions.
-
Click New Action.
-
Configure the new action.
-
Select Rules and click the rule that you want to monitor.
-
Select the Actions tab.
-
Make sure that the new action is selected.
-
Click OK.
-
Repeat Tripwire to Tripwire for each rule you want to monitor.
You are now ready to configure the log source in QRadar.
-
To configure QRadar to
receive events from a Tripwire device: From the Log Source Type list, select
the Tripwire Enterprise option.
For more information about your Tripwire device, see your vendor documentation.