Configuring syslog on Linux OS
Configuring Linux® OS to forward events by using the syslog protocol.
- Log in to your Linux OS device, as a root user.
Open the /etc/syslog.conf file and add the following facility information:
<ip_address> is the IP address of IBM® QRadar®.
- Save the file.
Restart syslog by typing the following command:
service syslog restart
- Log in to the QRadar Console.
Add a Linux OS log source on the QRadar
For more information about syslog, see the Linux documentation (https://www.linux.com/what-is-linux/).