Getting Data In

Is it possible to forward logs from QRadar to Splunk and still be able to correlate the data for each device in Splunk?

mlmcadams
Engager

We have many devices sending logs to QRadar. Is it possible to forward logs from QRadar to Splunk and still be able to correlate the data for each device in Splunk?

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

It all depends on how Qradar sends the logs. If you can get syslog out, then collect it via syslog in Splunk and extract the host name from the log file. That should be easy for Splunk to do. We do it the other way, Splunk -> Qradar using _SYSLOG_ROUTING. Qradar just can't parse the incoming data correctly for some reason. You'd think since it is regex based it would just work.......

0 Karma

Nilkanth
New Member

hi can you explain why Qradar just can't parse the incoming data correctly for some reason
because we are also facing same issue.We are using splunk as log collector only and via heavy forwarder we are receiving logs on Qroc (Qradra cloud version) with one LB in between.now the problem is none of the data is getting parsed at Qroc end.
for all logs we are getting only Datagateway IP as device address.
so my questions is does Splunk support as kind of integration.does splunk modify original log format.is there any way we can solve this mess

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...