Send logs to IBM QRadar
Create a stream that sends the logs of your applications to the URL of an IBM QRadar instance, in Azion Console or with the Azion API, and confirm the delivery.
You can send the logs of a stream to IBM QRadar from Azion Console or with the Azion API. To send the events of a Web Application Firewall to a SIEM instead of the requests of your applications, refer to Stream WAF events to a SIEM.
Data Stream sends each batch of log lines to a URL of your QRadar instance. The URL is the only setting of this endpoint, with no key or token to enter. The stream form sets the endpoint in the field labeled Connector, where QRadar is the IBM QRadar option. For the field and its bounds, refer to Endpoints.
This guide streams the requests of one workload through the Applications data source.
Select your interface here. The prerequisites and the tasks below follow that choice.
Prerequisites
- An Azion account with the Edit Data Stream permission. For the permissions, refer to Stream settings.
- A workload on the account that receives requests.
- Access to your IBM QRadar instance, to get the URL that receives the log lines.
- That URL, with its scheme, such as
https://qradar.example.com:14440.
- Access to Azion Console. To sign in, refer to How to access Azion Console.
Create the stream
The stream takes its logs from one workload, through a workload filter. Sampling would deactivate your other streams; a workload filter does not.
Send a POST request to https://api.azion.com/v4/workspace/stream/streams. In the body, replace <workload-id> with the ID of your workload and the url value with the URL of your QRadar instance. Replace [TOKEN VALUE] with your personal token:
The data source workloads is the API name of Applications, and template 2 is Applications Event Collector. The qradar endpoint takes url as its only attribute. The API answers 201 and returns the stored stream:
The id identifies the stream in later requests, such as /v4/workspace/stream/streams/12355. For every key of the body, refer to Stream settings.
Azion saves the stream without a call to the QRadar URL. A wrong URL shows only when the stream sends. The activation takes effect after one to two minutes.
Confirm the delivery
Real-Time Events keeps a record of each send of a stream, delivered or not, with the status code that the endpoint returned. Send a few requests to the workload and wait about one minute. A stream sends a batch every 60 seconds, or earlier when the batch reaches 2,000 log lines.
To read the sends with the API, query the dataStreamedEvents dataset of the Real-Time Events GraphQL API. Set the dates to a range that includes the activation of the stream:
The API answers 200 with one record per send, the latest first:
A send to QRadar carries QRADAR in endpointType. A statusCode of 200 means QRadar accepted the batch. The streamedLines and dataStreamed fields give the size of the batch in log lines and in bytes. If dataStreamedEvents is an empty list, the stream did not send in that range. For every field, refer to Real-Time Events GraphQL fields.
A status other than 200 comes from QRadar, except 503: that status means Data Stream found the endpoint unavailable. For the causes, refer to Troubleshoot Data Stream.