Configuring Trend Micro Deep Discovery Email Inspector to communicate with QRadar
To collect events from Trend Micro Deep Discovery Email Inspector, configure a syslog server profile for the IBM® QRadar® host.
- Log in to the Trend Micro Deep Discovery Email Inspector user interface.
- Click .
- Click Add.
- Verify that Enabled is selected for Status. The default is Enabled.
- Configure the following parameters:
Parameter Description Profile name Specify a name for the profile. Syslog server The host name or IP of the QRadar server. Port 514 Log format LEEF
- Select Detections, Virtual Analyzer Analysis logs, and System events for the types of events to send to QRadar.