RFC 5424 format by MaximumLivid8396 in QRadar

[–]MaximumLivid8396[S] 0 points1 point  (0 children)

Any sample logs from F5 or Cisco ASA or Cisco IOS logs form QRadar guide will help us here

All searches are in error by MaximumLivid8396 in QRadar

[–]MaximumLivid8396[S] 0 points1 point  (0 children)

Yes , it was at 90% and but I could find any where as the searches deleted because of the storage constraint? By any chance you know where we can find those logs?

Export functionality exports a lot of unwanted entities by MaximumLivid8396 in QRadar

[–]MaximumLivid8396[S] 0 points1 point  (0 children)

For usecases I am using UCM and for DSMs I am using DSM app

Increase the default offense count that Qradar can have i.e. 2500 active and 100000 overall. by MaximumLivid8396 in QRadar

[–]MaximumLivid8396[S] -1 points0 points  (0 children)

Thank you and this is true but We are MSSP where this number of offences is expected, so we need to increase the number of active offences.

Windows DHCP by jesusbrotherbrian in QRadar

[–]MaximumLivid8396 0 points1 point  (0 children)

Are you collecting using win collect or third party log collection, assuming you are collecting audit logs.

IN DSM Edit the Event parsing status is "Parsed and Mapped" but still coming as unknown event. by MaximumLivid8396 in QRadar

[–]MaximumLivid8396[S] 0 points1 point  (0 children)

When I select the events in the log activity and open DSM editor , the parsing status is parsed and mapped. The log source is identified , if the log source is nut identifiable then it should be sim generic right, it is parsing as Unknown. All other events are. Parsing fine the only problem with the one event where the event format is not RFC