VMware Cloud Community
TheVMinator
Expert
Expert
Jump to solution

Log Insight integration with 3rd Party SIEMs

Has anyone set up Log Insight to integrate with a third party SIEM like QRadar so that your events from VMware go first to Log Insight then get forwarded to your SIEM?  Any caveats with this? 

0 Kudos
1 Solution

Accepted Solutions
sflanders
Commander
Commander
Jump to solution

http://kb.vmware.com/kb/2053382

Hope this helps! === If you find this information useful, please award points for "correct" or "helpful". ===

View solution in original post

0 Kudos
5 Replies
sflanders
Commander
Commander
Jump to solution

Yup, it works Smiley Happy

Hope this helps! === If you find this information useful, please award points for "correct" or "helpful". ===
TheVMinator
Expert
Expert
Jump to solution

Ok great - thanks.  Can I choose to retain the source Ip when I forward, so that my third party SIEM will recognize the original source of the event?

0 Kudos
sflanders
Commander
Commander
Jump to solution

Not today -- LI behaves like any other syslog agent and sends its IP for source. Can you open a feature request on https://loginsight.vmware.com?

Hope this helps! === If you find this information useful, please award points for "correct" or "helpful". ===
0 Kudos
TheVMinator
Expert
Expert
Jump to solution

OK thanks - is there anything in the documentation or anywhere online that states that the source IP of the syslog event source is NOT retained?

0 Kudos
sflanders
Commander
Commander
Jump to solution

http://kb.vmware.com/kb/2053382

Hope this helps! === If you find this information useful, please award points for "correct" or "helpful". ===
0 Kudos