cancel
Showing results for 
Search instead for 
Did you mean: 

Qradar log forwarding with Extreme NAC

Qradar log forwarding with Extreme NAC

Jithishkk
New Contributor

Hello Team,

We are trying to forward the logs received in Extreme NAC to Qradar. We have added in the Qradar IP and port details.

We are receiving only header information from the Extreme NAC.

1. Any addition configuration required?

2. What is the Syslog format shared by Extreme NAC to Qradar.

Note : Qradar is receiving logs in LEEF format. 

 

 

2 REPLIES 2

Jithishkk
New Contributor

To add , Qradar is expecting the logs in LEEF format.

Please check this out

Adam_Minowski_1-1690287479199.png

SIEM configuration is refering directly to QRadar as QRadar was Extreme SIEM a time ago.

GTM-P2G8KFN