Qradar log forwarding with Extreme NAC
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎07-17-2023 08:28 AM
Hello Team,
We are trying to forward the logs received in Extreme NAC to Qradar. We have added in the Qradar IP and port details.
We are receiving only header information from the Extreme NAC.
1. Any addition configuration required?
2. What is the Syslog format shared by Extreme NAC to Qradar.
Note : Qradar is receiving logs in LEEF format.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎07-17-2023 08:29 AM
To add , Qradar is expecting the logs in LEEF format.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎07-25-2023 05:16 AM - edited ‎07-25-2023 05:18 AM
Please check this out
SIEM configuration is refering directly to QRadar as QRadar was Extreme SIEM a time ago.
