0

I have qradar setup on one host and vmware vsphere cloud setup on another host. My Vsphere cloud setup has one esxi host I want to send logs from of this esxi host to my qradar. How to do it.Please help.

Lalit Garghate
  • 119
  • 1
  • 5

2 Answers2

0
  1. Go to vSphere Web Client
  2. Click on Esxi host that you want to send logs to qradar
  3. Go to Configure -> Advance System Setting
  4. Click edit and filter keyword 'Syslog.global.logHost'
  5. put value as 'udp://:514' in 'Syslog.global.logHost' field.Click OK.
  6. Go to Configure -> Firewall
  7. Click edit and filter keyword 'syslog'
  8. Checked the syslog check box.Click OK.
Lalit Garghate
  • 119
  • 1
  • 5
0

I want to add information on point 8, the firewall menu can be accessed via the network tab to restrict access through the firewall

Zubair
  • 915
  • 2
  • 9
  • 28
yamin
  • 1