Configuring Cisco NAC to forward events

You can configure Cisco NAC to forward syslog events:

Procedure

  1. Log in to the Cisco NAC user interface.
  2. In the Monitoring section, select Event Logs.
  3. Click the Syslog Settings tab.
  4. In the Syslog Server Address field, type the IP address of your IBM QRadar.
  5. In the Syslog Server Port field, type the syslog port number. The default is 514.
  6. In the System Health Log Interval field, type the frequency, in minutes, for system statistic log events.
  7. Click Update.

    You are now ready to configure the log source in QRadar.