Configuring ESET Remote Administrator to communicate with QRadar
Configure your ESET Remote Administrator (ERA) server to send LEEF formatted syslog events to IBM QRadar.
About this task
Note:
The required parameters listed in the following steps are
configured in the Server Settings pane. To see a graphic, go to the ESET website.
(http://help.eset.com/era_admin/64/en-US/index.html?admin_server_settings_export_to_syslog.htm)Procedure
- Log in to your ERA web console.
- In the Admin navigation pane, click Server Settings.
- In the SYSLOG SERVER area, select the Use Syslog server check box.
- In the Host field, type the host name for your QRadar Event Collector.
- In the Port field, type 514.
- In the LOGGING area, select the Export logs to Syslog check box.
- From the Exported logs format list, select LEEF.
- Click Save.