Sending logs to QRadar
Snare agents can be configured to forward log data to QRadar, the following guide details the steps required with Snare to correctly configure delivery:
Login to the Snare agent.
From your Snare Enterprise Agent, navigate to the Destination Configuration page.
Under Network Destinations set:
To send logs to QRadar via Snare Central:
Domain/IP to your Snare Central destination
Port to 6161
Protocol to UDP or TCP (recommended)
Format to QRadar
To send logs directly to QRadar:
Domain/IP to your QRadar destination
Port to 514
Protocol to UDP or TCP (recommended)
Format to SYSLOG (RFC3164) or other. LEEF may be use though the Port will require updating.
Under Hostname Options tick the Host IP As Source checkbox and select the network adapter you would like to use as the IP override.
Select Update Destinations to save your page settings.
Click Apply Configuration & Restart Service menu item to update the registry.