Question & Answer
Question
This article informs administrators about QRadar® Support policies related to Custom Log Source Types created that use the DSM Editor or through legacy XML extensions. For Log Sources that do not have an official DSM, use a custom Log Source type to integrate Log Sources. A Log Source extension (also known as a device extension) is then applied to the custom Log Source type to provide the logic for parsing the logs. The Log Source extension is based on Java™ regular expressions and can be used against any protocol type, such as syslog, JDBC, and Log File. Values can be extracted from the logs and mapped to all common fields within IBM® QRadar®.
Answer
Responsibilities for Custom Log Sources and DSM editor issues
The DSM editor allows an administrator to create a custom parsing scheme when a custom Log Source is required. This document outlines out-of-scope work for custom Log Source cases and the responsibilities of the QRadar administrator.
Support type | Description | Responsibility |
Custom Log Source, DSM editor, and support |
QRadar technical support teams can assist administrators with errors, questions, and issues, such as:
|
QRadar technical support To open a case or report a Log Source error, contact QRadar technical support. |
Out-of-scope for QRadar Support | Administrators are responsible for custom Log Source types created in the DSM Editor. The following activities are considered out-of-scope for technical support cases:
Administrators need to create, tune, test, and maintain custom Log Sources by referring to the documentation.
|
|
[{"Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000cwsyAAA","label":"Admin Tasks"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Version(s)"}]
Was this topic helpful?
Document Information
Modified date:
29 June 2021
UID
ibm16427787