Sending logs to QRadar
Snare agents can be configured to forward log data to QRadar, the following guide details the steps required with Snare to correctly configure delivery:
Login to the Snare agent.
From your Snare Enterprise Agent, navigate to the Destination Configuration page.
Under Network Destinations set:
To send logs to QRadar via Snare Central:
Domain/IPÂ to your Snare Central destination
Port to 6161
Protocol to UDP or TCP (recommended)
Format to SNARE
To send logs directly to QRadar:
Domain/IPÂ to your QRadar destination
Port to 514
Protocol to UDP or TCP (recommended)
Format to SYSLOG (RFC3164) or other. LEEF may be use though the Port will require updating.
Under Hostname Options tick the Host IP As Source checkbox and select the network adapter you would like to use as the IP override.
Select Update Destinations to save your page settings.
Click Apply Configuration & Restart Service menu item to update the registry.