SUMMARY

The configuration settings are outlined below for sending events to IBM's QRadar in:

Snare Enterprise Agent for Windows

From your Snare Enterprise Agent, navigate to the Destination Configuration page and update the following settings:

Snare Central Server

The Snare Central Server Collector / Reflector is a very flexible tool for filtering and editing event log data. It is capable of filtering events on a per-destination basis. It can convert data from one format to another, and it can even modify the event information on the fly to suit your target SIEM server or syslog destination.

Navigate to System : Administrative Tools : Configure Collector/Reflector and select Settings > Destinations.  Update the following:

When sending logs to Snare Central to then be reflected to QRadar it is best to send the logs using Snare format to Snare Central then use the QRadar log format as above. The Agent should also use the host IP as a source override as it makes it easier for QRadar to parse out the logs from the reflector.