QRadar CE Adding DSMs

preview_player
Показать описание

ERRATA: Leopoldo Aguirre (A.K.A Polo) pointed out that finding a DSM in the Log Source icon does not means that the DSM/parser is actually installed. If you ssh into the console and type rpm -qa | grep DSM you will see the DSMs installed.

Link to download the ISO image:

Link to the Box folder with the index to more QRadar videos:
Рекомендации по теме
Комментарии
Автор

Could I suggest this topic should have been added into your video "Adding Windows Logs to Qradar CE". Thankfully it did roll over to this video, but I was wondering why I had "unknown event log"

Ralph