Question & Answer
Question
In IBM Security QRadar you need two components in order to parse logs correctly. One is a protocol, such as syslog, the other part is a DSM parser. When you are dealing with cloud-based deployments, the QRadar protocol portions are API-based. QRadar supports several API-based protocols out-of-the-box, such as AWS or Azure.
Many cloud-based deployments or apps frequently change capabilities and configuration requirements. To better support these fast-paced environments, QRadar provides a Universal Cloud REST API Protocol, which enables you to keep ingesting log data from those cloud-based log sources.
In this course, Jose Bravo explains and demonstrates how to configure a setup using the Log Source Management app.
Duration: 14 Minutes
Follow the link in related information to view the course on the IBM Security Learning Academy
Log InLog in to view more of this document
Was this topic helpful?
Document Information
Modified date:
28 October 2020
UID
ibm16356815