Created on 08-23-2021 02:33 PM - edited 09-16-2022 07:43 AM
I am looking for documentation, examples and other prior art for integrating Ranger logs with IBM QRadar. Our Security team uses QRadar for log filtering and monitoring and requires we send our audit logs to a QRadar event hub for audits.
Created 08-31-2021 04:47 AM
Hi We don't have any specific documentation, But the ranger audit logs will be stored in solr, If possible you can query the audits using solr and you can make an integration from solr to IBM QRadar
Created 09-12-2021 10:52 PM
@wjsandman, Has the reply helped resolve your issue? If so, please mark the appropriate reply as the solution, as it will make it easier for others to find the answer in the future.
Regards,
Vidya Sargur,Created 09-13-2021 06:00 AM
Just saw this reply... not alot of direction, but better than nothing. I'll have a look and reply.
Created 09-13-2021 07:53 AM
Sure, will wait for your response. Thanks @wjsandman.
Regards,
Vidya Sargur,