CONFIGURE LOG SOURCE
-
Navigate to the Admin tab
-
Navigate to Data Sources > Events. Click Log Sources
-
Double-click on the Log Source Virsec Security Platform
-
Configure the log source as described below:
-
If QRadar Log Source Management app is NOT installed, configure the below parameter:
-
Log Source Identifier – Provide the VSP CMS IP Address OR the IP Address from where QRadar receives the notifications
-
Target Event Collector – For QRadar on Cloud, provide the on-premise data gateway from the dropdown
-
Parameters such as Listen Port, Communication Type can also be modified if required
-
Click Save
-
-
If QRadar Log Source Management app is installed, a pop-up window is displayed. Click Launch
-
Click Log Sources
-
Search for Virsec Security Platform and press enter. Select the listed entry
-
Select the tab Protocol
-
Click Edit
-
Log Source Identifier - Provide the CMS IP address OR the IP Address from where QRadar receives the notifications
-
Parameters such as Listen Port, Communication Type can also be modified if required. It is recommended to change only the IP address and retain the default values for other parameters
-
Click Save
-
-
-
On the Admin tab of the QRadar SIEM console, click Deploy Changes to activate the newly configured log source
-
Depending on the environment, IP Table modifications may be required on the QRadar instance OR data collector to allow the configured Listen Port