If the tcpdump command lists events, but no events are shown on the
log activity, then the syslog events are not received by the IBM
QRadar Console.
Procedure
-
Review your system notifications.
-
If the system notifications display the incorrect source address for the log source, choose one
of the following options:
- Manually re-create the log source.
- Update the Log Source Identifier field with the correct host name or
IP address.
-
Verify that the device supports QRadar automatic discovery.
The IBM
QRadar DSM Configuration Guide
appendix lists which Device Support Modules (DSMs) support automatic log source
creation.
-
Verify that the log sources in QRadar match the tcpdump
results.
-
Search for the log source host name or packet IP address in the tcpdump results.
-
Click the Admin tab.
-
On the navigation menu, click Data Sources.
-
In the Events pane, click Log Sources.
-
Search for the log source host name or packet IP address.
If the QRadar host
name or packet IP address does not match the tcpdump results, then the log source might be created
with an incorrect address. For some devices, unexpected values occur in the syslog header when the
event source handles events from multiple devices. Your device might be able to preserve the
original event IP address before the syslog event is sent.
-
Search for a unique payload value in QRadar.
-
Review the tcpdump raw payloads.
-
Select an identifier that is unique to your event source.
-
Click the Log Activity tab.
-
On the toolbar, click Add Filter.
-
From the Parameter menu, select Payload
Contains.
-
In the Value field, type your unique identifier.
-
Review the search results.
What to do next
If the results return a different log source, then an auto-detection false positive occurred.
Delete the wrongly detected log source.
If the log source is discovered incorrectly, verify that your QRadar
Console is installed with the latest
DSM version. Rediscover the log source.