Ingest logs from Qradar to Azure sentinel.

%3CLINGO-SUB%20id%3D%22lingo-sub-3270692%22%20slang%3D%22en-US%22%3EIngest%20logs%20from%20Qradar%20to%20Azure%20sentinel.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3270692%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20All%2C%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20working%20on%20one%20project%20and%20trying%20to%20ingest%20data%20from%20Qradar%20to%20azure%20sentinel.%20That%20would%20appriciated%20if%20any%20help%20me%20on%20this%26nbsp%3B%20like%20any%20document%20or%20any%20link.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3270692%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESIEM%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3294707%22%20slang%3D%22en-US%22%3ERe%3A%20Ingest%20logs%20from%20Qradar%20to%20Azure%20sentinel.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3294707%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1203325%22%20target%3D%22_blank%22%3E%40ankit976%3C%2FA%3E%26nbsp%3Byou%20can%20forward%20QRadar%20logs%20as%20syslog%20as%20explained%20here%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fwww.ibm.com%2Fdocs%2Fen%2Fqsip%2F7.5%3Ftopic%3Dadministration-forward-data-other-systems%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EQRadar%20Forwarding%20Destination%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThen%20those%20logs%20can%20be%20forwarded%20to%20Sentinel%20via%20one%20of%20our%20agents%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ERegards%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hello All, 

I am working on one project and trying to ingest data from Qradar to azure sentinel. That would appriciated if any help me on this  like any document or any link.

1 Reply

@ankit976 you can forward QRadar logs as syslog as explained here: QRadar Forwarding Destination

 

Then those logs can be forwarded to Sentinel via one of our agents

 

Regards