Entries for log management

The log management attributes that are associated with the QRadarĀ® feature are placed under various log entries that depend on the attributes.

cn=default, cn=Log Management, cn=configuration
Applies to all log management entries unless they are overwritten by specifying the settings explicitly in the individual log entries.
cn=<specific_log_name>, cn=Log Management, cn=configuration
Applies only to the log specified by the entry. The default settings for this log can be overwritten by specifying the settings in this entry. The values for <specific_log_name> are ibmslapd, audit, tools, bulkload, admin, admin audit, db2cli, replication, and ddsetup.

The configuration attributes that are associated with QRadar integration can be placed only under cn=Audit, cn=Log Management, cn=Configuration.