We have a customer who is using Content Security Reporter to collect logs from their Web Gateway. We would now like to send logs to SIEM (QRadar) as well.
As part of the process, we need to import the Log Handler downloadable from the QRadar site. Will this alter the format of the logs in the AccessLogs (and potentially other log files) and cause Content Security Reporter to stop recognising the logs?
If yes, is there a way to have two different log handlers for the Web Gateway, one to handle CSR logs and one to handle a log format for a second log log collector?
Thanks for getting back to me. I realise that it is possible to send to QRadar and I have read the community document you are referring to.
The question here is the fact that Web Gateway is sending logs to other sources already (CSR and another). If I import the QRadar log handler, how would that affect the format of the logs being sent to the other two. I cannot afford to cause any interruptions to existing syslog targets because I changed the log format and they can now no longer be parsed. Does this make sense? Is there a solution that could help me send logs in different formats to different syslog target receivers.
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.