Configuring an off-site target

To forward event and flow data to an Event Collector in another deployment, configure the source deployment to include an off-site target so that it knows which computer to send the data to.

Before you begin

You must know the listening ports for the off-site target appliance. By default, the listening port for events is 32004, and 32000 for flows.
To find the listening port on the target appliance, follow these steps:
  1. In the target deployment, click the System and License Management icon.
  2. Select the host and click Deployment Actions > Edit Host.
  3. Click the Component Management settings icon (Settings icon), and find the ports in the Event Forwarding Listening Port and Flow Forwarding Listening Port fields.

About this task

To prevent connection errors, when you configure off-site source and target components, deploy the IBM QRadar Console with the off-site source first. Then, deploy the QRadar Console with the off-site target.

Procedure

  1. On the navigation menu ( Navigation menu icon ), click Admin.
  2. In the System Configuration section, click System and License Management.
  3. In the Display list, select Systems.
  4. On the Deployment Actions menu, click Manage Off-site Targets.
  5. Click Add and configure the parameters.

    The name can be up to 20 characters in length and can include underscores or hyphens. The default port to listen for events is 32004, and 32000 for flows.

    In the IP field, enter the IP address of the QRadar Console of the destination deployment.

    Note: If the off-site target is a managed host with encrypted host connections to its console, port 22 for SSH opens no matter which port is selected in the user interface.
  6. Click Save.
  7. Click Manage Connections to specify which QRadar hosts you want to receive the data.

    Only hosts that have an Event Collector are shown in the list.

  8. Repeat the steps to configure all off-site targets that you want to configure.
  9. On the Admin tab, click Deploy changes.