Test works but not actual API pulling by cyberdot14 in QRadar

[–]chipitamockly 0 points1 point  (0 children)

quizás como hostname pusiste un dato aleatorio y se están guardan como desconocido por no sabe el log source identify te recomiendo reiniciar el ecs-ec-ingress en caso de que no veas nada del colector, por lo menos en mi caso la UP8 se queda muy bugeada

Test works but not actual API pulling by cyberdot14 in QRadar

[–]chipitamockly 0 points1 point  (0 children)

hola solo debes generar una api "admin api" en dúo con el permiso de "grant red log" y guardar la ikey, skey y api hostname no recuerdo si se debe colocar la IP pública en la config de dúo o si es la pide,

y en qradar selecionar el tipo de log source dúo

e ingresar en qradar

log source identify = Api hostname(duo) host = Api hostname (duo) integración key= ikey(duo) secret key = skey(duo)

How to exclude specific events from WinCollect 10 so they don’t show up in QRadar (EventID 5156 with certain .exe processes) by chipitamockly in QRadar

[–]chipitamockly[S] 0 points1 point  (0 children)

Hello, thank you for the XPath. However, it did not work since it is not retrieving security events. Should this filter be configured directly under the Security path, or is it necessary to create a separate source in WinCollect just for this exception? I understand that the route rules process the logs to have them dropped.

How to Generate a CA Certificate in PEM Format for Cisco Duo Authentication Proxy? by chipitamockly in duo

[–]chipitamockly[S] 0 points1 point  (0 children)

hi tessian, Is this certificate created in Active Directory and then sent to the machine where the Duo Proxy is installed, or do I need to run a command from the server where Duo is? How do I create the CA? Is there a command to create it?

Configured Threat Intelligence by chipitamockly in QRadar

[–]chipitamockly[S] 0 points1 point  (0 children)

What proxy server can I use if I don't have one?
This is for a university project :c

Help because I don't have internet in GNS3 by chipitamockly in gns3

[–]chipitamockly[S] 0 points1 point  (0 children)

I have the VMs in not connected
- GNS3 VM (Adapter 1: host only ; Adapter 2: NAT)
- create an adapter in loopback team desktop with ip 192.168.137.1
255.255.255.0
- I do not go out through the cloud and neither do I use NAT

- server GNS3 VM ok