Configuring QRadar log integration by using Web Administration Tool

Enable and configure QRadar® log integration with the Web Administration Tool so that you can manage the server audit logs for IBM® Security Verify Directory activities.

About this task

The attributes that are related to QRadar integration settings in the following steps are saved in IBM Security Verify Directory under the cn=Audit, cn=Log Management, cn=Configuration entry.

Procedure

  1. If you did not do so already, click Server administration in the Web Administration navigation area.
  2. Click Logs in the expanded list.
  3. Click Modify log settings.
  4. In the Log Name column, click Server audit log.
  5. Under Server audit log settings, click Log Management Integration.
  6. Select Enable QRadar Integration.
  7. In the Host field, specify the host name or IP address of the QRadar server.

    When you specify the host name or IP address, the value is stored and read from the configuration file.

    If you do not specify a value in this field, local host is used by default.

    The attribute ibm-slapdLogEventQRadarHostName is associated with this field.

  8. In the Syslog Port field, specify the syslog port number on which the QRadar server listens.

    When you specify the syslog port number, the value is stored and read from the configuration file

    If you do not specify a value in this field, 514 is assigned as the default syslog port number. For more information, see Ports used by QRadar.

    The attribute ibm-slapdLogEventQRadarPort is associated with this field.

  9. In the Map file location field, specify the path and file name of the map file that sets up the various QRadar attributes for the event.

    The default location on a Linux system is /opt/ibm/ldap/V10.0.2/idstools/idslogmgmt/.

    The attribute ibm-slapdLogEventQRadarMapFilesLocation is associated with this control.

  10. Click Finish to save the changes and return to the Modify log settings page.

Start the log management service.

The primary administrator and local administrative group members with AuditAdmin or ServerConfigGroupMember role can start and stop the log management service.

  1. Click Logs under Server administration in the Web Administration navigation area.
  2. Click Start/Stop log management in the expanded list.
  3. Click Start.

    If the log management service is already started and you want to stop the service, click Stop.