Edge with QRadar
Answers
-
Hi @Dan Fisk, have you tried a pipeline to convert the events into the WinCollect or Snare syslog formats? This way you don't have to write too much custom parsing on the QRadar side.
This might help you get started:
1 -
This doc might contain helpful tips too: Managing Qradar Licenses
0