Announcements

SecurID® Discussions

Browse the SecurID discussion board to get product help and collaborate with other SecurID users.
ArKarOo
Beginner
Beginner

integrating AM 8.1 with QRadar SIEM 7.2.5

Jump to solution

I am involved in a project that uses above products and need to forward AM 8.1 virtual appliance logs to qradar siem. I haven't found any updated guide on achieving this here and at IBM guide. May I know if anyone has configuration guide to achieve this integration?

0 Likes
1 Solution

Accepted Solutions
JamesMandelbaum
Employee
Employee

If you log in to the Security Console and go to the menus: Setup ->System Setup -> Logging ;you will be able to select the instance you want to configure and provide the IP Address of the QRadar server for the syslog to go.

 

You can do this for each replica and they can all go to the same server or different servers based on your needs.

View solution in original post

0 Likes
2 Replies
JamesMandelbaum
Employee
Employee

If you log in to the Security Console and go to the menus: Setup ->System Setup -> Logging ;you will be able to select the instance you want to configure and provide the IP Address of the QRadar server for the syslog to go.

 

You can do this for each replica and they can all go to the same server or different servers based on your needs.

0 Likes
JochenHoffmann
Occasional Contributor
Occasional Contributor

Hi,

 

additionally, you may consider using SNMP for monitoring / alerting purposes: logon to Security Console using an account w/ administrative permissions and select "Setup > System Settings > Network Monitoring (SNMP)". Please keep in mind, AM 8.x uses SNMP v3 with authentication & authorization.

 

Cheers,

Jochen.

0 Likes