BeyondTrust Privilege Management for Unix, Linux and Networked Devices

The IBM QRadar DSM for BeyondTrust Privilege Management for Unix, Linux and Networked Devices logs all events to a multi-line format in a single event log that is viewed by using Beyond Trust's pblog utility.

Note: BeyondTrust Privilege Management for Unix, Linux and Networked Devices was previously called BeyondTrust PowerBroker.

You must be on a Linux®, Unix or AIX® operating system to integrate BeyondTrust Privilege Management for Unix, Linux and Networked Devices with QRadar.

To integrate BeyondTrust Privilege Management for Unix, Linux and Networked Devices with QRadar, complete the following steps:
  1. If automatic updates are not enabled, RPMs are available for download from the IBM® support website (http://www.ibm.com/support). Download and install the most recent version of the BeyondTrust Privilege Management for Unix, Linux and Networked Devices DSM RPM on your QRadar® Console.
  2. Configure BeyondTrust Privilege Management for Unix, Linux and Networked Devices to communicate with QRadar. See Configuring BeyondTrust Privilege Management for Unix, Linux and Networked Devices to communicate with QRadar.

For more information about TLS syslog log source parameters, see TLS syslog protocol configuration options.