You can configure a route for syslog events in Active Defense for QRadar.
Procedure
-
Log in to the Active Defense Management Console.
-
From the navigation menu, select .
-
Click Add Route.
-
In the Route Name field, type a name for the syslog route you are adding
to Active Defense.
-
From the Route Type list, select LEEF (Q1
Labs).
-
In the Settings pane, configure the following values:
- Host - Type the IP address or hostname for your QRadar
Console or Event Collector.
- Port - Type 514 as the port number.
-
In the Events pane, select any events that you want to forward to QRadar.
-
Click OK to save your configuration changes.
The Active Defense device configuration is complete. You are now ready to configure a log source
in QRadar. For more
information on configuring a route in Active Defense, see your HBGary Active Defense User
Guide.