Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
HPACHPANDE
Explorer

Need Help on log forwarding for specific log forwarding to SIEM (User activity,Configuration chang)

Hello Folks,


We are receiving logs from all blades As mentioned below 

 
 

VPN-1 & FireWall-1
Anti Malware
New Anti Virus
Syslog
SmartDefense
Security Gateway/Management
WEB_API
Identity Awarenes
Threat Emulation


But Concern here is we are not seeing any user login/logout failed/success events. Also no any log is recorded for Firewall Configuration change.

Kindly let me know how we can get those logs in Qradar SIEM

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

The logs you receive depend entirely on the Log Exporter configuration.
How precisely is this configured?
What version/JHF is the management?

You did not list Mobile Access in the above "blades" list which I believe is how Remote Access VPN logins will show up.
Audit logs must be exported explicitly.

0 Kudos
Upcoming Events

    CheckMates Events