Syslog data source parameters for Zscaler NSS
If the QRadar® product does not automatically detect the data source, add a Zscaler NSS log source by using Data Ingestion Manager.
When you use the Syslog connector, there are specific parameters that you must use.
|
Parameter |
Description |
|---|---|
| Data Source type | Zscaler NSS |
| Connector Configuration | Syslog |
| Data Source Identifier |
Type the IP address as an identifier for events from your Zscaler NSS installation. The data source identifier must be a unique value. |
| Enabled |
By default, the check box is selected. |
| Credibility |
Select the credibility of the data source. The range is 0 - 10. The credibility indicates the integrity of an event or offense as determined by the credibility rating from the source devices. Credibility increases if multiple sources report the same event. The default is 5. |
| Target Event Collector |
Select the Target Event Collector to use as the target for the data source. |
| Coalescing Events |
Select this option for the data source to coalesce (bundle) events. By default, automatically discovered data sources inherit the value of the Coalescing Events list from the System Settings in the QRadar product. When you create a data source or edit an existing data source configuration, you can override the default value by configuring this option for each data source. |
| Incoming Event Payload |
Select the Incoming Payload Encoder option for parsing and storing the logs from the list. |
| Store Event Payload |
Select this option to enable the data source to store event payload information. By default, automatically discovered data sources inherit the value of the Store Event Payload list from the System Settings in the QRadar product. When you create a data source or edit an existing configuration, you can override the default value by configuring this option for each data source. |
| Data Source Language |
Select the language of the events that are generated by Zscaler NSS. |
For more information about adding a data source, see Adding ingestion data sources.