Enable and configure QRadar® log
integration with the Web Administration Tool so that you can manage
the server audit logs for IBM® Security Verify
Directory activities.
About this task
The attributes that are related to QRadar integration settings in the following
steps are saved in IBM Security Verify
Directory under the cn=Audit, cn=Log Management, cn=Configuration entry.
Procedure
- If you did not do so already, click Server administration in
the Web Administration navigation area.
- Click Logs in the expanded list.
- Click Modify log settings.
- In the Log Name column, click Server
audit log.
- Under Server audit log settings,
click Log Management Integration.
- Select Enable QRadar Integration.
- In the Host field, specify the host
name or IP address of the QRadar server.
When you specify the host name or IP address, the value is
stored and read from the configuration file.
If you do not specify
a value in this field, local host is used by default.
The attribute ibm-slapdLogEventQRadarHostName is
associated with this field.
- In the Syslog Port field, specify
the syslog port number on which the QRadar server
listens.
When you specify the syslog port number, the
value is stored and read from the configuration file
If you
do not specify a value in this field, 514 is assigned as the default
syslog port number. For more information, see Ports used by QRadar.
The
attribute ibm-slapdLogEventQRadarPort is associated
with this field.
- In the Map file location field,
specify the path and file name of the map file that sets up the various QRadar attributes for the event.
The default location on a Linux system is /opt/ibm/ldap/V10.0.2/idstools/idslogmgmt/.
The
attribute ibm-slapdLogEventQRadarMapFilesLocation is
associated with this control.
- Click Finish to save the changes
and return to the Modify log settings page.
Start the log management service.
The
primary administrator and local administrative group members with AuditAdmin or ServerConfigGroupMember role
can start and stop the log management service.
- Click Logs under Server
administration in the Web Administration navigation area.
- Click Start/Stop log management in
the expanded list.
- Click Start.
If the
log management service is already started and you want to stop the
service, click Stop.