IBM Support

QRadar Universal Cloud REST API Protocol

Question & Answer


Question

In IBM Security QRadar you need two components in order to parse logs correctly. One is a protocol, such as syslog, the other part is a DSM parser. When you are dealing with cloud-based deployments, the QRadar protocol portions are API-based. QRadar supports several API-based protocols out-of-the-box, such as AWS or Azure. 

Many cloud-based deployments or apps frequently change capabilities and configuration requirements. To better support these fast-paced environments, QRadar provides a Universal Cloud REST API Protocol, which enables you to keep ingesting log data from those cloud-based log sources.

In this course, Jose Bravo explains and demonstrates how to configure a setup using the Log Source Management app.


Duration: 14 Minutes
Follow the link in related information to view the course on the IBM Security Learning Academy

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Version","Edition":" ","Line of Business":{"code":"LOB77","label":"Automation Platform"}}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
28 October 2020

UID

ibm16356815