Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Description

Config Example

Designated for Windows Event Logs.

Expand
titleRequest Json

{name: "qradartrans", type: "transform", configuration: "{\n \"mapping\": {\n \"@timestamp\": {\n \"column\": \"date\"\n },\n \"log.level\": {\n \"column\": \"type\"\n },\n \"message\": {\n \"column\": \"y\"\n },\n \"event.code\": {\n \"column\": \"x\"\n },\n \"event.provider\": {\n \"column\": \"category\"\n },\n \"event.kind\": {\n \"const\": \"event\"\n },\n \"event.created\": {\n \"column\": \"date\"\n }\n }\n}"}

QRadar

The data flow should be defined with the ‘QRadar’ condition, inside the relevant forwarder:

Image RemovedImage Added

Output: The target receives the win event logs in a LEEF format (a customized event format for QRadar).

Image RemovedImage Added