We have a customer who is using Content Security Reporter to collect logs from their Web Gateway. We would now like to send logs to SIEM (QRadar) as well.
As part of the process, we need to import the Log Handler downloadable from the QRadar site. Will this alter the format of the logs in the AccessLogs (and potentially other log files) and cause Content Security Reporter to stop recognising the logs?
If yes, is there a way to have two different log handlers for the Web Gateway, one to handle CSR logs and one to handle a log format for a second log log collector?
Hope you are doing well.
You can configure syslog settings on MWG in order to send logs to SIEM (QRadar).
Please refer below link for detailed information on the same:-
Download the new ePolicy Orchestrator (ePO) Support Center Extension which simplifies ePO management and provides support resources directly in the console. Learn more about ePO Support Center