Skip to main content
ted_barker
New Member
November 1, 2016
Question

IBM Qradar, experienced users? What custom tweaking done etc.

  • November 1, 2016
  • 4 replies
  • 7194 views
We use IBM Qradar and I saw that they have a FortiGate DSM that tries to interpret Fortigate syslogs. Usually those are only basics and many input fields are not properly mapped, one of the things I checked immediately, was on how they identify the vdom's. And it looks like they did not define this as a property. Has anyone experience using Qradar with FortiGate and what custom tweaking did they do? What is the best log guide available? Detailed description of messages and what they mean?

4 replies

ted_barker
New Member
April 11, 2017

Any QRADAR users in the forum?

 

One of the initial issues faced is that we want to have the VDOMs reported as separate devices. Any other company that already did some modification?

Kenundrum
New Member
April 11, 2017

You can use the per-vdom syslog overrides to trick your system into seeing the traffic coming from different devices. If your SIEM doesn't have an interpreter that can use the vdom tags, it most likely uses the syslog source ip to identify devices- I've seen other products that do it similarly.

You can use the CLI commands "config log syslogd override-setting" and "set source-ip <ip address>" to do this. You set the parameter per vdom and the syslogs will appear to be coming from whatever ip address you choose instead of the management interface of the box. For sanity, you want to make sure to have each vdom source be an interface that actually exists on the vdom.

ted_barker
New Member
April 11, 2017

Thanks for the info.

 

Going to check it out.

 

What is the impact on performance on a 1500D with 10 VDOMs and around 700 to 1500 logs per second? Does it have an impact and will it be measurable and consistent?

 

But actually I was hoping that Fortinet creates a better DSM for QRADAR or maybe they have and all I need is to tweak it.

 

QRADAR is according to some Fortinet documents a supported SIEM, not sure who created the DSMs (IBM or Fortinet) and if they have they should include proper VDOM handling. Or at least explain how to use it.

 

I also have this issue with FAZ, as I would like to have a global view over multiple VDOMs and a per VDOM filter on FortiView. Today it seems not possible.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!