Resolving unreceived syslog events

If the tcpdump command lists events, but no events are shown on the log activity, then the syslog events are not received by the IBM QRadar Console.

Procedure

  1. Review your system notifications.
  2. If the system notifications display the incorrect source address for the log source, choose one of the following options:
    • Manually re-create the log source.
    • Update the Log Source Identifier field with the correct host name or IP address.
  3. Verify that the device supports QRadar automatic discovery.
    The IBM QRadar DSM Configuration Guide appendix lists which Device Support Modules (DSMs) support automatic log source creation.
  4. Verify that the log sources in QRadar match the tcpdump results.
    1. Search for the log source host name or packet IP address in the tcpdump results.
    2. Click the Admin tab.
    3. On the navigation menu, click Data Sources.
    4. In the Events pane, click Log Sources.
    5. Search for the log source host name or packet IP address.
    If the QRadar host name or packet IP address does not match the tcpdump results, then the log source might be created with an incorrect address. For some devices, unexpected values occur in the syslog header when the event source handles events from multiple devices. Your device might be able to preserve the original event IP address before the syslog event is sent.
  5. Search for a unique payload value in QRadar.
    1. Review the tcpdump raw payloads.
    2. Select an identifier that is unique to your event source.
    3. Click the Log Activity tab.
    4. On the toolbar, click Add Filter.
    5. From the Parameter menu, select Payload Contains.
    6. In the Value field, type your unique identifier.
    7. Review the search results.

What to do next

If the results return a different log source, then an auto-detection false positive occurred. Delete the wrongly detected log source.

If the log source is discovered incorrectly, verify that your QRadar Console is installed with the latest DSM version. Rediscover the log source.