Configuring Linux® OS to forward events by using the syslog protocol.
Procedure
-
Log in to your Linux OS device, as a root user.
-
Open the /etc/syslog.conf file and add the following facility information:
where:
<ip_address> is the IP address of IBM
QRadar.
-
Save the file.
-
Restart syslog by typing the following command:
service syslog restart
-
Log in to the QRadar
Console.
-
Add a Linux OS log source on the QRadar
Console.
For more information about syslog, see the Linux documentation
(https://www.linux.com/what-is-linux/).