I just need a sanity check here. I have a customer with multiple VSs running on some 21ks. For reasons too lengthy to go into on this thread they are moving all VSs to physical clusters. I moved the first VS to a 6800 cluster last weekend.
The customer has QRadar setup to the customer's CMA with an OPSEC/Lea connection. They are telling me they are not seeing logs from the new cluster, but still see all of the old logs as they would expect. All logs are visible in the log server including the new hardware cluster.
I am fairly certain on this, but this customer is making me doubt myself. If you have an OPSEC/Lea connection to a log server, there is no way to filter which logs are sent, right? Or which FW logs are sent. It has to be something on the QRadar side that is filtering I would think.
Am I mistaking here? Or is there something that I'm missing which is obvious?
Thanks,
Paul