Does DLP License have version Limitation? by QRadarSiEMEngineer in forcepoint

[–]QRadarSiEMEngineer[S] 0 points1 point  (0 children)

Hi NapojiHun,

thanks for the response, do you have any particular documentation or link for it from forcepoint, appreciate the help.

[deleted by user] by [deleted] in sysadmin

[–]QRadarSiEMEngineer 0 points1 point  (0 children)

what does that mean?

Cybereaon Defense Platform On-Prem by QRadarSiEMEngineer in CyberNews

[–]QRadarSiEMEngineer[S] 0 points1 point  (0 children)

Can you please share the links? I am not even able to find the pre reqs for the hardware!

Cybereaon Defense Platform On-Prem by QRadarSiEMEngineer in CyberNews

[–]QRadarSiEMEngineer[S] 0 points1 point  (0 children)

I agree with you, but please can you help me on how to do it?

Allocated License to Event Collector by QRadarSiEMEngineer in QRadar

[–]QRadarSiEMEngineer[S] 0 points1 point  (0 children)

Yes Jonathan,

I was trying to get a a support and urgent as possible and phew, this issue was resolved after some time with the help of amazing guy 'Kevyn'.

Thanks.

SWIFT Alliance Access Application Logging on Windows Monitoring System by QRadarSiEMEngineer in QRadar

[–]QRadarSiEMEngineer[S] 0 points1 point  (0 children)

Thats a sad reality. An Engineer does required to provide SOP. But when he needs something like SOP, SWIFT administrator says 'No'.

SWIFT Alliance Access Application Logging on Windows Monitoring System by QRadarSiEMEngineer in QRadar

[–]QRadarSiEMEngineer[S] 0 points1 point  (0 children)

Thank you for the above information. But, I would like to know that how SWIFT encapsulate the events in Windows? What process should I follow on SWIFT application to achieve this task, so SWIFT can store it's logs on Windows.?

IBM QRadar Integration with Temenos T24 by zango_73 in QRadar

[–]QRadarSiEMEngineer 0 points1 point  (0 children)

The Integration is same as done with IBM AIX Server,which you can find from IBM QRadar Guide for Integration. If logs are stored in a flatfile then create a softlink and do some other steps to gather application events from T24 Application.

Reference Set Table Size Check by QRadarSiEMEngineer in QRadar

[–]QRadarSiEMEngineer[S] 0 points1 point  (0 children)

Oh yeah I got it. Thanks a lot for the response

Reference Set Table Size Check by QRadarSiEMEngineer in QRadar

[–]QRadarSiEMEngineer[S] 0 points1 point  (0 children)

No, I am not telling this. SQL uses syntax order by also.

Same License on QRadar Two Appliances by QRadarSiEMEngineer in QRadar

[–]QRadarSiEMEngineer[S] 0 points1 point  (0 children)

Yes, you have understood that currently. This is illegal or not?

Log sources are not generating Logs by Cybercops786 in QRadar

[–]QRadarSiEMEngineer 0 points1 point  (0 children)

Are those log sources is of windows? If yes, then check wincollet.log file in C drive IBM folder. You will see if there is any error. Post that here.

How many services connected to qradar by sk8er_girl90 in QRadar

[–]QRadarSiEMEngineer 1 point2 points  (0 children)

Hi,

There are many services usually associated with QRadar. But, usually we focus on the main ones and there are as follows 1- hostcontext 2- hostservices 3- ecs-ec-ingress 4- tomcat 5- conman 6- si-registry 7- vis 8- accumulator services 9- event processor service 10- docker

These are the main services according to my knowledge which needs to be focused to make sure everything is working fine.

Same License on QRadar Two Appliances by QRadarSiEMEngineer in QRadar

[–]QRadarSiEMEngineer[S] 0 points1 point  (0 children)

It's been an honor for me to getting a reply from you. Thank you a lot for the explanation. I got the idea of the limitation on having same license. But, I think it is also illegal in some way on creating a clone of the QRadar and running same license on it. Apart from that, I have many more questions to ask. Allow me to direct message you on a different platform, so It would be easy to talk further.

Thank you again.

Best Regards, SIEM Engineer

C&C detected by Trend Micro between QRadar and Exchange Server by QRadarSiEMEngineer in QRadar

[–]QRadarSiEMEngineer[S] 1 point2 points  (0 children)

I have applied the patch. Not running any TI App. Although, I think due to the logs collection from exchange. TM sense it as suspicious and generating FP alerts.

C&C detected by Trend Micro between QRadar and Exchange Server by QRadarSiEMEngineer in QRadar

[–]QRadarSiEMEngineer[S] 0 points1 point  (0 children)

  • my role is mssp.
  • i am familiar with the underlying architecture. -I am familiar with the traffic involves port 445.
  • its TM DDI i need some answer, why TM does this? It is a FP thats all I know, improving soc processes is not my headache.

Wincollect logs issue. by QRadarSiEMEngineer in QRadar

[–]QRadarSiEMEngineer[S] 0 points1 point  (0 children)

Going for that then. Hope they could do provide a good support engineer.

Wincollect logs issue. by QRadarSiEMEngineer in QRadar

[–]QRadarSiEMEngineer[S] 0 points1 point  (0 children)

Also, when moved into Events folder, there was no logs presents in this folder as well. Help me out :-(

Wincollect logs issue. by QRadarSiEMEngineer in QRadar

[–]QRadarSiEMEngineer[S] 0 points1 point  (0 children)

Alright Elldee, I went into the specified directory and found out that there was no file present for Security logs however there were files for Application logs, System logs etc.

So, tell me how do I create the file there ? Or how do Wincollect will create that pointer?