IBM Support

QRadar: For Logsource configuration using Log File Protocol (SFTP/FTP) on Windows devices use correct remote directory format

Troubleshooting


Problem

When configuring a logsource for a Windows end device, using the log file protocol in QRadar, administrators may commonly use the standard Windows path format, such as C:\support\logs. However, this is a frequent point of misconfiguration.

Symptom

Administrators may see errors like below while performing Test for the logsource:
image-20240916113554-1

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000cwt0AAA","label":"Log Source"}],"ARM Case Number":"TS016360677","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
11 October 2024

UID

ibm17168106