I have qradar setup on one host and vmware vsphere cloud setup on another host. My Vsphere cloud setup has one esxi host I want to send logs from of this esxi host to my qradar. How to do it.Please help.
Asked
Active
Viewed 2,499 times
2 Answers
0
- Go to vSphere Web Client
- Click on Esxi host that you want to send logs to qradar
- Go to Configure -> Advance System Setting
- Click edit and filter keyword 'Syslog.global.logHost'
- put value as 'udp://:514' in 'Syslog.global.logHost' field.Click OK.
- Go to Configure -> Firewall
- Click edit and filter keyword 'syslog'
- Checked the syslog check box.Click OK.

Lalit Garghate
- 119
- 1
- 5