IBM Support

QRadar: How to ingest events with LogFile protocol from a rotating system- or application log file on Linux (Proof of concept)

How To


Summary

The two main methods of collecting events from Linux OS-based hosts; Syslog and LogFile protocols. This article describes an example of how ingestion might work by using LogFile protocol on httpd logs.
Note: This log source type and protocol combination is undocumented, and not officially supported. IBM Support cannot troubleshoot problems with receiving event data. Events received by an undocumented protocol might be in a format unrecognized by the DSM. Use the DSM Editor to resolve any parsing issues.

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000cwt0AAA","label":"Log Source"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
24 November 2023

UID

ibm16857843