On the Lastline Enterprise system, use the SIEM settings in the notification interface to
specify a SIEM appliance where Lastline can send events.
Procedure
-
Log in to your Lastline Enterprise system.
-
On the sidebar, click Admin.
-
Click .
-
To add a notification, click the Add a notification (+)
icon.
-
From the Notification Type list, select
SIEM.
-
In the SIEM Server Settings pane, configure the parameters
for your QRadar
Console or Event Collector. Ensure that you select LEEF
from the SIEM Log Format list.
-
Configure the triggers for the notification:
-
To edit existing triggers in the list, click the Edit
trigger icon, edit the parameters, and click
Update Trigger.
-
To add a trigger to the list, click the Add
Trigger (+) icon, configure the parameters, and click
Add Trigger.
-
Click Save.