Configuring Sourcefire Intrusion Sensor
To configure your Sourcefire Intrusion Sensor, you must enable policy alerts and configure your appliance to forward the event to QRadar®.
Procedure
- Log in to your Sourcefire user interface.
- On the navigation menu, select Intrusion Sensor > Detection Policy > Edit.
- Select an active policy and click Edit.
- Click Alerting.
- In the State field, select on to enable the syslog alert for your policy.
- From the Facility list, select Alert.
- From the Priority list, select Alert.
- In the Logging Host field, type the IP address of the QRadar Console or Event Collector.
- Click Save.
- On the navigation menu, select Intrusion Sensor > Detection Policy > Apply.
- Click Apply.
What to do next
You are now ready to configure the log source in QRadar.