To enable FireEye to communicate with IBM
QRadar, configure your FireEye
appliance to forward syslog events.
Procedure
- Log in to the FireEye appliance by using the CLI.
- To activate configuration mode, type the following commands:
enable
configure terminal
- To enable rsyslog notifications, type the following command:
-
To add QRadar as an
rsyslog notification consumer, type the following command:
fenotify rsyslog trap-sink QRadar
-
To specify the IP address for the QRadar system that you want to
receive rsyslog trap-sink notifications, type the following command:
fenotify rsyslog trap-sink QRadar address
<QRadar_IP_address>
- To define the rsyslog event format, type the following
command:
fenotify rsyslog trap-sink QRadar prefer message format
leef
- To save the configuration changes to the FireEye appliance,
type the following command: