SYSLOG format for QRadar SIEM

This section lists the CARLa fields that installation-defined alerts and extended monitoring alerts generate for use with IBM Security QRadar SIEM.

For example, installation-defined alerts that are to be sent to IBM Security QRadar SIEM must include a whoUSERID tag. QRadar chooses this tag for setting the Username field. To let QRadar SIEM search, view, and report on tags other than whoUSERID, you can create QRadar SIEM custom event and flow properties. This topic is discussed in the Custom Event and Flow Properties chapter of the IBM Security QRadar SIEM Users Guide, as well as in the QRadar SIEM built-in product help system.

Installation-defined alerts generate the following CARLa fields:
RFC5424 field CARLa field
eventResult return code of RACINIT (logon) request access_result
fromWhereCONSOLE source of the command console
fromWhereTERMINAL terminal (LU name) where logon occurred terminal, acf2_source
fromWhereSRCIP IPv4 address if terminal is hexadecimal terminal(hextoip)
fromWhereSYSTEM JES2 node name of remote job entry (NJE) utoken_snode
fromWhereUSER User that submitted job, if different from current user (SURROGAT) utoken_suser, acf2_submitter
onWhatACTION action action
onWhatALLOWED allowed (permitted) access on resource access
onWhatAUTHORITY authority/privilege that allowed access/command SPEC, OPER, AUDIT, ROAUDIT, SECURITY, READALL, NON-CNCL
onWhatCLASS class of resource class
onWhatDSNAME data set name dsname
onWhatGranted intended and allowed (actual) access, duplicate of onWhatINTENT intent, acf2_access
onWhatGROUP-AUTHORITY authority (privilege) specified on CONNECT SPEC, OPER
onWhatINTENT intended (actual) access intent, acf2_access
onWhatMEMBER member name member
onWhatNEW-PERMISSIONS new permissions new_permissions
onWhatOLD-PERMISSIONS old permissions old_permissions
onWhatPROFILE profile protecting resource profile, acf2_rulekey
onWhatRACFCMD-AUTH authority specified on CONNECT racfcmd_auth (CREATE,CONNECT,JOIN)
onWhatRACFCMD-GROUP group specified on PERMIT/CONNECT racfcmd_group
onWhatRACFCMD-NAME name of user specified on PERMIT/CONNECT racfcmd_user:name
onWhatRACFCMD-USER user specified on PERMIT/CONNECT racfcmd_user, acf2_rulekey
onWhatRESOURCE resource resource
onWhatSENSTYPE reason why resource is privileged/sensitive senstype, PCI-AUTH, PCI-PAN, PCI-PAN-clr, Site-Dsn-R, Site-Dsn-U,
onWhatUNIX-ACCESS-ALLOWED allowed (permitted) access unix_access_allowed
onWhatUNIX-ACCESS-INTENT intended (actual) access unix_access_intent
onWhatUNIX-PATHNAME pathname unix_pathname
onWhatVOLUME (disk) volume volume
whatACTION action keyword action
whatApplication ZWS application  
whatATTEMPTS number of attempts count
whatChangedFields fields modified by privilege escalation  
whatCommands number of commands issued count
whatCOUNT-SMF-LOST lost SMF records  
whatDESC description of RACF EVENT desc, acf2_descriptor
whatEVENT RACF EVENT event
whatJOBID job number jobid
whatJOBNAME job name jobname
whatPARM parameter on a command value of UACC, ID(*), WARNING, LEVEL( ), acf2_changes
whatPROGRAM program active in privilege escalation  
whatPASSWORDCHANGES number of password changes count
whatRACFCMD RACF command racfcmd
whatRULE ACF2 RULE protecting resource acf2_rulekey
whatSTC started task id stc
whatUACC universal access permitted value from RACFCMD
whatVIOLATIONS count of access failures count
whatWTO-MESSAGE WTO message WTO message texts
whenSMF_FAILURE start of SMF loss  
whereAPPL application used in logon appl
wherePOE source of logon utoken_poeclass and/or utoken_poe
whereSYSTEM system where event occurred system or :runsystem
whoNAME name of user userid:name
whoUSERID user id userid, acfstcid
blank means this is not a standard CARLa field, but picked up from the SYSLOG msg, or a literal value inserted by the alert skeleton.
Extended Monitoring (COMPAREOPT) alerts use the hourly internal snapshots to identify changes in the system. These alerts generate the following CARLa fields:
RFC5424 field Meaning CARLa field
whatACTION   Change_IPConfig, Change_IPConfig_Log, Change_IPConfig_Log_Default, Change_APF_List, Change_IPConfig, ChangeSVC, Change_Security_Activate_Class, Change_Security_Inactivate_Class
onWhatAPF data set APF authorized apf
onWhatAPFLIST data set in APF list apflist
onWhatCLASS RACF class class
onWhatCURR-ADDRESS SVC current address curr_address
onWhatCURR-APF SVC current APF protected state curr_apf
onWhatDSNAME dsname dsname
onWhatESRNO SVC extended routing number esrno
onWhatStatus RACF class active active
onWhatSVCNO SVC number svcno
onWhatVOLUME volser volume
whatChangedFields fields names of modified fields comp_change
whatCODE code dump code
whatDSTIP dest IP dstip
whatDSTPFXLEN dest prefix dstpfxlen
whatDSTPORT dest port dstport
whatLOG RACF log option on class log
whatKindOfChange ADD, DEL, CHG comp_result
whatPROTOCOL network protocol protocol
whatROUTING routing rule routing
whatSECCLASS SAF class secclass
whatSRCIP src IP srcip
whatSRCPFXLEN src prefix srcpfxlen
whatSRCPORT src port srcport
whatTYPE type of rule type
whereCOMPLEX RACF database complex complex
whereINTERFACE network interface interface
whereSTACK IP stack name stack
whereSYSTEM system system
Note: A blank in the CARLa field column means that this is not a standard CARLa field, but it is picked up from the SYSLOG message, or the alert skeleton inserted a literal value.