To collect Microsoft SharePoint LOGbinder events, you must configure your LOGbinder SP
system to send events to IBM®
QRadar®.
Procedure
-
Open the LOGbinder SP Control Panel.
-
Double-click Output in the Configure pane.
-
Choose one of the following options:
- Configure for Syslog-Generic output:
- In the Outputs pane, double-click
Syslog-Generic.
- Select the Send output to Syslog-Generic
check box, and then enter the IP address and port of your QRadar Console or Event Collector.
- Configure for Syslog-LEEF output:
- In the Outputs pane, double-click
Syslog-LEEF.
- Select the Send output to Syslog-LEEF check
box, and then enter the IP address and port of your QRadar Console or Event Collector.
-
Click OK.
-
To restart the LOGbinder service, click the Restart
icon.