Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Salma
Explorer
Jump to solution

Log exporter TLS config with QRadar

Hello,

I am trying to configure log exporter with TLS to send LEEF format events to QRadar.

I followed the steps here: 

QRadar link: https://www.ibm.com/support/knowledgecenter/SS42VS_DSM/com.ibm.dsm.doc/t_dsm_guide_Checkpoint_tls_en... 

Checkpoint link: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut... 

But the handshake is not established because of an unknown certificate error.

The issue may be because of the signed certificate that I generated.

I also saw in other questions that this issue can be related to the Common Name used when generating the root CA.

Any advice here please?

Thanks,

Salma

 

0 Kudos
1 Solution

Accepted Solutions
Salma
Explorer

Hi,

Thank you all.

The issue was resolved with IBM:

1- generate the certificates following this tech note: https://www.ibm.com/docs/en/dsm?topic=point-integrating-check-by-using-tls-syslog 

  •  for each certificate (rootCA, log_exporter, and syslogServer), use a different CN (any string, it doesn't have to be an IP)

2- put the rootCA files in /etc/pki/ca-trust/source/anchors/

3- run this command: update-ca-trust

And it worked!

Hope this will help.

Bes,

Salma

View solution in original post

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

It would help if you posted the precise error message you received.
Not to mention version/JHF level of all relevant components.

0 Kudos
Chris_Atkinson
Employee Employee
Employee
0 Kudos
Salma
Explorer

Hi,

Thank you all.

The issue was resolved with IBM:

1- generate the certificates following this tech note: https://www.ibm.com/docs/en/dsm?topic=point-integrating-check-by-using-tls-syslog 

  •  for each certificate (rootCA, log_exporter, and syslogServer), use a different CN (any string, it doesn't have to be an IP)

2- put the rootCA files in /etc/pki/ca-trust/source/anchors/

3- run this command: update-ca-trust

And it worked!

Hope this will help.

Bes,

Salma

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events