Use the REMOTE SYSLOG SETUP widget to enable remote system logging
and to configure protocol details.
Procedure
-
In QRadar® Network Packet Capture, click the
ADMIN tab.
-
Go to the REMOTE SYSLOG SETUP widget.
-
Select the Remote Syslog Enabled check box to enable system
logging.
Select Only log LEEF if you
want to capture only Log Event Extended Format (LEEF) syslog events.
Figure 1. Remote Syslog Setup widget
-
Check UDP or TCP protocol according to
your settings.
-
Specify a port number for the Remote Syslog Server Port and an IP
address for the Remote Syslog Server fields.
-
Click Apply.