ForeScout CounterACT

The ForeScout CounterACT DSM for IBM® QRadar® accepts Log Event Extended Format (LEEF) events from CounterACT using syslog.

QRadar records the following ForeScout CounterACT events:

  • Denial of Service (DoS)
  • Authentication
  • Exploit
  • Suspicious
  • System