IBM Support

QRadar: DSM Editor and custom log source cases and support policies

Question & Answer


Question

This article informs administrators about QRadar® Support policies related to Custom Log Source Types created that use the DSM Editor or through legacy XML extensions. For Log Sources that do not have an official DSM, use a custom Log Source type to integrate Log Sources. A Log Source extension (also known as a device extension) is then applied to the custom Log Source type to provide the logic for parsing the logs. The Log Source extension is based on Java™ regular expressions and can be used against any protocol type, such as syslog, JDBC, and Log File. Values can be extracted from the logs and mapped to all common fields within IBM® QRadar®.

[{"Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000cwsyAAA","label":"Admin Tasks"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Version(s)"}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
29 June 2021

UID

ibm16427787