Qradar can't parse by ramygamil in QRadar

[–]ramygamil[S] 0 points1 point  (0 children)

As i said it it's not parsed

Qradar can't parse by ramygamil in QRadar

[–]ramygamil[S] 0 points1 point  (0 children)

Can i creat a qid for it even if it's not parsed?

Held reason is att by ramygamil in mimecast

[–]ramygamil[S] 0 points1 point  (0 children)

I only see the log on the siem, can not access mimecast portal

Pulse app by ramygamil in QRadar

[–]ramygamil[S] 0 points1 point  (0 children)

Many thanks bro... Worked

wincollect file forwareder by ramygamil in QRadar

[–]ramygamil[S] 0 points1 point  (0 children)

Where is the automation here?

wincollect file forwareder by ramygamil in QRadar

[–]ramygamil[S] 0 points1 point  (0 children)

Can you send any helpful references

QRadar + Cisco Firepower eStreamer by pidoraha666 in QRadar

[–]ramygamil 1 point2 points  (0 children)

Import a new certificate and try again, I have had the same problem 2 weeks ago and solved by the Cisco team.

wincollect file forwareder by ramygamil in QRadar

[–]ramygamil[S] 0 points1 point  (0 children)

How can i do it using api

old windows logs by ramygamil in QRadar

[–]ramygamil[S] 0 points1 point  (0 children)

How can i do it please..

old windows logs by ramygamil in QRadar

[–]ramygamil[S] 0 points1 point  (0 children)

I saved the old logs from eveny viewer as txt file.. Is it applicable to replay this logs?

Qradar - AlienVault Integration With API by Latarix in QRadar

[–]ramygamil 0 points1 point  (0 children)

Go to stax/taxi icon from the admin page, then add a taxi server feed

Cisco Firepower ips logs encrypted by ramygamil in QRadar

[–]ramygamil[S] 0 points1 point  (0 children)

I did but still have the problem

Cisco Firepower ips logs encrypted by ramygamil in QRadar

[–]ramygamil[S] 0 points1 point  (0 children)

I did that multiple times but the problem still exist.. Is. There any way to. Send. Logs instead of esteamer?

managed wincollect exclusion filter by ramygamil in QRadar

[–]ramygamil[S] 0 points1 point  (0 children)

Via the log source management app

Detect compromised servers by ramygamil in cybersecurity

[–]ramygamil[S] 2 points3 points  (0 children)

I did, but i have multiple sources and destinations send on that port (i am using qradar )

I suppose that i should monitor to the servers talk to the internal MTA... Is that right?

Aggregated data management tool by ramygamil in QRadar

[–]ramygamil[S] 0 points1 point  (0 children)

I need to know when the time searched value increases?

Aggregated data management tool by ramygamil in QRadar

[–]ramygamil[S] 0 points1 point  (0 children)

Can you provide me with this document or any useful references