Getting Data In

Is it possible to forward logs from QRadar to Splunk and still be able to correlate the data for each device in Splunk?

mlmcadams
Engager

We have many devices sending logs to QRadar. Is it possible to forward logs from QRadar to Splunk and still be able to correlate the data for each device in Splunk?

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

It all depends on how Qradar sends the logs. If you can get syslog out, then collect it via syslog in Splunk and extract the host name from the log file. That should be easy for Splunk to do. We do it the other way, Splunk -> Qradar using _SYSLOG_ROUTING. Qradar just can't parse the incoming data correctly for some reason. You'd think since it is regex based it would just work.......

0 Karma

Nilkanth
New Member

hi can you explain why Qradar just can't parse the incoming data correctly for some reason
because we are also facing same issue.We are using splunk as log collector only and via heavy forwarder we are receiving logs on Qroc (Qradra cloud version) with one LB in between.now the problem is none of the data is getting parsed at Qroc end.
for all logs we are getting only Datagateway IP as device address.
so my questions is does Splunk support as kind of integration.does splunk modify original log format.is there any way we can solve this mess

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...