Configuring IBM QRadar Network Packet Capture to communicate with QRadar

To collect IBM® QRadar® Network Packet Capture events, you must configure a remote Syslog server for your IBM QRadar Network Packet Capture appliance.

Procedure

  1. Log in to your IBM QRadar Network Packet Capture appliance as administrator.
  2. Click Admin.
  3. In the REMOTE SYSLOG SETUP pane, enable system logging.
  4. Enable the UPD or TCP protocol, depending on your transfer settings.
  5. In the Remote Syslog Server Port field, type the port number that you want to use to send remote syslog events. The default port number for remote syslog is 514.
  6. In the Remote Syslog Server field, type the IP address for your QRadar Event Collector to which you want to send events.
  7. Click Apply.
    Note: QRadar parses only LEEF events for IBM QRadar Network Packet Capture. On the Log Activity tab in QRadar, the Event Name displays as IBM QRadar Packet Capture Message and the Low Level Category displays as Stored for all other events.