Configuring remote syslog alert objects

Create remote system log alert objects to add a record to the remote log file when a network access policy rule, an intrusion prevention rule, an IPS event filter rule, an advanced threat policy, or an OpenSignature policy is triggered. You can also configure remote syslog alert objects to enable the appliance to record system events in a remote log file.

About this task

If the connection to the remote syslog server drops, the IBM QRadar Network Security appliance generates a System Alert. If you are using TCP protocol, the appliance writes the events to an offline storage file. When the connection is restored, events stored in this file are sent to the remote syslog server. If the connection is not restored before the storage file exceeds 10MB, any additional events are dropped. The Network Security appliance generates another System Alert when the connection is reestablished.

Navigating in the Local Management Interface: Use one of the following paths to navigate to the policy or to the page where you want to create a response object:
  • Secure > Network Access Policy
  • Secure > Intrusion Prevention Policy
  • Secure > IPS Event Filter Policy
  • Secure > Advanced Threat Policy
  • Secure > OpenSignature Policy
  • Manage > Management Policy
  • Manage > System Alerts
Navigating in the SiteProtector™ System:
  1. Select the Policy view.
  2. In the My Sites pane, expand the Locally Configured Agents menu item, and then select your Network Security agent.
  3. In the Local Policies pane, select one of the following options:
    • Network Access Policy
    • Intrusion Prevention Policy
    • IPS Event Filter Policy
    • Advanced Threat Policy
    • OpenSignature Policy
    • SiteProtectorManagement
    • Management Access Policy
    • System Alerts
  4. Click Action > Open.
Note: If you migrated your policy to another repository in the SiteProtector System, open the policy from that location.

Procedure

  1. From one of the following locations, begin to add or edit a remote syslog alert object:
    Location Options
    Network Objects or IPS Objects pane
    • Click New > Response > Alert > Remote Syslog to create a remote syslog alert object.
    • Expand Response > Alert > Remote Syslog, select an existing remote syslog alert object, and then click Edit to edit it.
    ATP Objects pane
    • Click New > Alert > Remote Syslog to create a remote syslog alert object.
    • Expand Alert > Remote Syslog, select an existing remote syslog alert object, and then click Edit to edit it.
    System Alerts page
    • Click New > Alert > Remote Syslog to create a remote syslog alert object.
    • In the Added Objects or Available Objects pane, select an existing remote syslog alert object, and then click Edit to edit it.
    Tip: You can also create or edit network objects when you configure a network access policy rule.
  2. In the Add or Edit Remote Syslog Object window, configure the following options:
    Option Description
    Name Specifies a meaningful name for the response.
    Remote Syslog Collector Specifies the fully qualified domain name or IP address of the host on which you want to save the log.
    Note: The host must be accessible to the appliance.
    Remote Syslog Collector Port Specifies the custom port that is used to connect to the syslog collector. The default is 514.
    Remote Syslog Collector Protocol Specifies the protocol that is used to connect to the syslog collector.
    Note: If you select TCP protocol, and the appliance loses the connection to the remote syslog server, some event data could be dropped.
    QRadar Format Enabled Enables the appliance to send events in QRadar LEEF format instead of RFC5424 remote syslog format.
    Comment A comment that identifies the remote syslog alert object.
  3. Click Save Configuration.

What to do next

After you configure a remote syslog alert object, perform one of the following actions so that the appliance initiates the response when specified events occur:
  • Add the object to one or more rules in a policy
  • Add the object to the Added Objects pane on the System Alerts page
Note: After you create or edit alert objects that are used by a rule in a policy, you must deploy the updated policy for the changes to take effect.