Skip to main content
rakesh_kumar
New Member
March 9, 2020
Question

Logging in IBM LEEF format issue

  • March 9, 2020
  • 3 replies
  • 5818 views

Hi Everyone,

 

We have configured our Fortiweb to send logs to QRadar SIEM.

For that we have used this "log siem-policy", which is pretty straight forward.

 

But when it reaches to SIEM, its not parsing. Further investigation and IBM acknowledged that, every attribute of the log should be separated by the "tab", but currently fortiweb is sending the logs separated with "space".

 

My main concern is, if there is a option to select 'IBM LEEF' in logging, then it should match what IBM is expecting.

Why we are seeing a discrepancy here.

 

Anyone who have gone thru this, please revert.

SS attached

 

 

 

Regards,

Rakesh

    3 replies

    abelio
    SuperUser
    SuperUser
    March 9, 2020

    Hi,

    every qualified siem (as qradar is)  has the capabilities to parse logs from different sources and formats.

    'tab' or 'space' separators are very common, so it should be solve adjusting parser in the Qradar site.

     

     

     

    rakesh_kumar
    New Member
    March 9, 2020
    Hi Abelio, Thanks for the response. Actually we are using the same setting "Log Policy > SIEM Policy" and using IBM LEEF as 'set type'. When we asked IBM about logs not getting parsed under Universal Leef, they are saying this should only be separated by tab. Space not supported Regards Rakesh
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.