SYSLOG format for QRadar SIEM
This section lists the CARLa fields that installation-defined alerts and extended monitoring alerts generate for use with IBM Security QRadar SIEM.
For example, installation-defined alerts that are to be sent to IBM Security QRadar SIEM must include a whoUSERID tag. QRadar chooses this tag for setting the Username field. To let QRadar SIEM search, view, and report on tags other than whoUSERID, you can create QRadar SIEM custom event and flow properties. This topic is discussed in the Custom Event and Flow Properties chapter of the IBM Security QRadar SIEM Users Guide, as well as in the QRadar SIEM built-in product help system.
Installation-defined alerts generate the following CARLa fields:
blank means this is not a standard CARLa field, but picked up from the SYSLOG msg, or a
literal value inserted by the alert skeleton.
| RFC5424 field | CARLa field | |
| eventResult | return code of RACINIT (logon) request | access_result |
| fromWhereCONSOLE | source of the command | console |
| fromWhereTERMINAL | terminal (LU name) where logon occurred | terminal, acf2_source |
| fromWhereSRCIP | IPv4 address if terminal is hexadecimal | terminal(hextoip) |
| fromWhereSYSTEM | JES2 node name of remote job entry (NJE) | utoken_snode |
| fromWhereUSER | User that submitted job, if different from current user (SURROGAT) | utoken_suser, acf2_submitter |
| onWhatACTION | action | action |
| onWhatALLOWED | allowed (permitted) access on resource | access |
| onWhatAUTHORITY | authority/privilege that allowed access/command | SPEC, OPER, AUDIT, ROAUDIT, SECURITY, READALL, NON-CNCL |
| onWhatCLASS | class of resource | class |
| onWhatDSNAME | data set name | dsname |
| onWhatGranted | intended and allowed (actual) access, duplicate of onWhatINTENT | intent, acf2_access |
| onWhatGROUP-AUTHORITY | authority (privilege) specified on CONNECT | SPEC, OPER |
| onWhatINTENT | intended (actual) access | intent, acf2_access |
| onWhatMEMBER | member name | member |
| onWhatNEW-PERMISSIONS | new permissions | new_permissions |
| onWhatOLD-PERMISSIONS | old permissions | old_permissions |
| onWhatPROFILE | profile protecting resource | profile, acf2_rulekey |
| onWhatRACFCMD-AUTH | authority specified on CONNECT | racfcmd_auth (CREATE,CONNECT,JOIN) |
| onWhatRACFCMD-GROUP | group specified on PERMIT/CONNECT | racfcmd_group |
| onWhatRACFCMD-NAME | name of user specified on PERMIT/CONNECT | racfcmd_user:name |
| onWhatRACFCMD-USER | user specified on PERMIT/CONNECT | racfcmd_user, acf2_rulekey |
| onWhatRESOURCE | resource | resource |
| onWhatSENSTYPE | reason why resource is privileged/sensitive | senstype, PCI-AUTH, PCI-PAN, PCI-PAN-clr, Site-Dsn-R, Site-Dsn-U, |
| onWhatUNIX-ACCESS-ALLOWED | allowed (permitted) access | unix_access_allowed |
| onWhatUNIX-ACCESS-INTENT | intended (actual) access | unix_access_intent |
| onWhatUNIX-PATHNAME | pathname | unix_pathname |
| onWhatVOLUME | (disk) volume | volume |
| whatACTION | action keyword | action |
| whatApplication | ZWS application | |
| whatATTEMPTS | number of attempts | count |
| whatChangedFields | fields modified by privilege escalation | |
| whatCommands | number of commands issued | count |
| whatCOUNT-SMF-LOST | lost SMF records | |
| whatDESC | description of RACF EVENT | desc, acf2_descriptor |
| whatEVENT | RACF EVENT | event |
| whatJOBID | job number | jobid |
| whatJOBNAME | job name | jobname |
| whatPARM | parameter on a command | value of UACC, ID(*), WARNING, LEVEL( ), acf2_changes |
| whatPROGRAM | program active in privilege escalation | |
| whatPASSWORDCHANGES | number of password changes | count |
| whatRACFCMD | RACF command | racfcmd |
| whatRULE | ACF2 RULE protecting resource | acf2_rulekey |
| whatSTC | started task id | stc |
| whatUACC | universal access permitted | value from RACFCMD |
| whatVIOLATIONS | count of access failures | count |
| whatWTO-MESSAGE | WTO message | WTO message texts |
| whenSMF_FAILURE | start of SMF loss | |
| whereAPPL | application used in logon | appl |
| wherePOE | source of logon | utoken_poeclass and/or utoken_poe |
| whereSYSTEM | system where event occurred | system or :runsystem |
| whoNAME | name of user | userid:name |
| whoUSERID | user id | userid, acfstcid |
Extended Monitoring
(COMPAREOPT) alerts use the hourly internal snapshots to identify changes in the system.
These alerts generate the following CARLa fields:
| RFC5424 field | Meaning | CARLa field |
| whatACTION | Change_IPConfig, Change_IPConfig_Log, Change_IPConfig_Log_Default, Change_APF_List, Change_IPConfig, ChangeSVC, Change_Security_Activate_Class, Change_Security_Inactivate_Class | |
| onWhatAPF | data set APF authorized | apf |
| onWhatAPFLIST | data set in APF list | apflist |
| onWhatCLASS | RACF class | class |
| onWhatCURR-ADDRESS | SVC current address | curr_address |
| onWhatCURR-APF | SVC current APF protected state | curr_apf |
| onWhatDSNAME | dsname | dsname |
| onWhatESRNO | SVC extended routing number | esrno |
| onWhatStatus | RACF class active | active |
| onWhatSVCNO | SVC number | svcno |
| onWhatVOLUME | volser | volume |
| whatChangedFields | fields names of modified fields | comp_change |
| whatCODE | code dump | code |
| whatDSTIP | dest IP | dstip |
| whatDSTPFXLEN | dest prefix | dstpfxlen |
| whatDSTPORT | dest port | dstport |
| whatLOG | RACF log option on class | log |
| whatKindOfChange | ADD, DEL, CHG | comp_result |
| whatPROTOCOL | network protocol | protocol |
| whatROUTING | routing rule | routing |
| whatSECCLASS | SAF class | secclass |
| whatSRCIP | src IP | srcip |
| whatSRCPFXLEN | src prefix | srcpfxlen |
| whatSRCPORT | src port | srcport |
| whatTYPE | type of rule | type |
| whereCOMPLEX | RACF database complex | complex |
| whereINTERFACE | network interface | interface |
| whereSTACK | IP stack name | stack |
| whereSYSTEM | system | system |
Note: A blank in the CARLa field column means that this is not a standard CARLa field, but
it is picked up from the SYSLOG message, or the alert skeleton inserted a literal value.