Configuring NCC Group DDoS Secure to communicate with QRadar
The NCC Group DDoS Secure DSM for IBM QRadar receives events from NCC Group DDoS Secure devices by using syslog in Log Event Extended Format (LEEF) format. QRadar records all relevant status and network condition events.
Procedure
- Log in to NCC Group DDoS Secure.
- Go to the Structured Syslog Server window.
- In the Server IP Address(es) field, type the IP address of the QRadar Console.
- From the Format list, select LEEF.
- Optional: If you do not want to use the default of local0 in the Facility field, type a syslog facility value.
- From the Priority list, select the syslog priority level that you want to include. Events that meet or exceed the syslog priority level that you select are forwarded to QRadar.
- In the Log Refresh (Secs) field, specify a refresh update time for structured logs. The refresh update time is specified in seconds.
- In the Normal Peak Bandwith field, specify the expected normal peak bandwidth of the appliance.