To collect events with QRadar, you must configure
your IBM® Security Network IPS (GX) appliance to enable syslog
forwarding of LEEF events.
Before you begin
Ensure that no firewall rules block the communication between your IBM Security Network IPS (GX) appliance and QRadar.
Procedure
- Log in to your IPS Local Management Interface.
-
From the navigation menu, select .
- Select the Enable Local Log check
box.
- In the Maximum File Size field,
configure the maximum file size for your LEEF
log file.
- From the Remote Syslog Servers pane, select the Enable
check box.
-
In the Syslog Server IP/Host field, type the IP address of your QRadar
Console or Event Collector.
- In the TCP Port field, type 514
as the port for forwarding LEEF log events.
Note: If you use v4.6.1 or earlier, use
the UDP Port field.
-
From the event type list, enable any event types that are forwarded to QRadar.
- If you use a TCP port, configure the crm.leef.fullavp
tuning parameter:
-
From the navigation menu, select .
- Click Add Tuning Parameters.
- In the Name field, type
crm.leef.fullavp.
- In the Value field, type
true.
- Click OK.