Configuring "Syslog event timeout" for each type of log source is not possible. However, you can identify the log sources that are not sending data by creating a daily report that you can configure.
- Log in to the QRadar UI as Administrator.
- On the navigation menu ( ), click the Report tab.
- Click the Actions button and select Create.
- In the Report Wizard select the time period you want to report > click Next.
- Select scheduled to generate the report > click Next.
- Select a Layout > click Next.
- Enter a Report Title and Chart Type = Log Source.
- Create a Chart Title.
- In the Log Sources section, select the log sources you want to report on. (You can check the box for All log sources)
- Scroll to the bottom of the window there is a Data Options field, check Only include log sources that have not reported for, box, and set the time frame to match the Syslog Event Timeout threshold configuration in System Settings.
- Click Save Container Details > click Next.
- Review the layout > click Next.
- Select the report format > click Next.
- Select the report distribution channel > click Next.
- Create a report description > click Next.
- Report Summary > click Finished.
Was this topic helpful?
04 February 2021