cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted

Web Gateway and Log Handlers

Hi

We have a customer who is using Content Security Reporter to collect logs from their Web Gateway. We would now like to send logs to SIEM (QRadar) as well.

As part of the process, we need to import the Log Handler downloadable from the QRadar site. Will this alter the format of the logs in the AccessLogs (and potentially other log files) and cause Content Security Reporter to stop recognising the logs?

If yes, is there a way to have two different log handlers for the Web Gateway, one to handle CSR logs and one to handle a log format for a second log log collector?

Many thanks

Labels (1)
2 Replies
McAfee Employee aloksard
McAfee Employee
Report Inappropriate Content
Message 2 of 3

Re: Web Gateway and Log Handlers

Hi Jebotha,

Hope you are doing well.

 

You can configure syslog settings on MWG in order to send logs to SIEM (QRadar).

 

Please refer below link for detailed information on the same:-

 

https://community.mcafee.com/t5/Documents/Web-Gateway-Understanding-and-Configuring-Syslog-for-your-...

 

Regards

Alok Sarda

Re: Web Gateway and Log Handlers

Hi Alok

Thanks for getting back to me. I realise that it is possible to send to QRadar and I have read the community document you are referring to.

The question here is the fact that Web Gateway is sending logs to other sources already (CSR and another). If I import the QRadar log handler, how would that affect the format of the logs being sent to the other two. I cannot afford to cause any interruptions to existing syslog targets because I changed the log format and they can now no longer be parsed. Does this make sense? Is there a solution that could help me send logs in different formats to different syslog target receivers.

Thanks
Jacques