Dear All I would like to know if there has been any integration done among syslog-ng OSE with Juniper Secure Analytics. Regards, Muhammad Asim | Senior Systems Engineer - ME, Pakistan | Juniper Networks, Inc. | (M) +923018510555 (O) +92518435204, +92518445530
Well, it should work as long as the other product accepts syslog. On Jun 6, 2015 7:58 AM, "Muhammad Asim" <masim@juniper.net> wrote:
Dear All
I would like to know if there has been any integration done among *syslog-ng OSE* with *Juniper Secure Analytics*.
Regards, *Muhammad Asim* | Senior Systems Engineer - ME, Pakistan | Juniper Networks, Inc. | (M) +923018510555 (O) +92518435204, +92518445530
______________________________________________________________________________ Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng FAQ: http://www.balabit.com/wiki/syslog-ng-faq
Thanks, the main objective is to reduce the EPS rate towards the SIEM which is Juniper Secure Analytics (QRadar). So my question is if the syslog-ng OSE is getting 100K logs/sec then would I able to send those logs to the QRadar system with reduce EPS rate i.e 2500EPS. From: syslog-ng-bounces@lists.balabit.hu [mailto:syslog-ng-bounces@lists.balabit.hu] On Behalf Of Scheidler, Balázs Sent: 08 June 2015 11:40 To: Syslog-ng users' and developers' mailing list Subject: Re: [syslog-ng] Syslog-ng OSE with Juniper SIEM Well, it should work as long as the other product accepts syslog. On Jun 6, 2015 7:58 AM, "Muhammad Asim" <masim@juniper.net<mailto:masim@juniper.net>> wrote: Dear All I would like to know if there has been any integration done among syslog-ng OSE with Juniper Secure Analytics. ______________________________________________________________________________ Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng FAQ: http://www.balabit.com/wiki/syslog-ng-faq
Hi, "Muhammad Asim" <masim@juniper.net> írta 2015-06-08 07:46-kor:
Thanks, the main objective is to reduce the EPS rate towards the SIEM which is Juniper Secure Analytics (QRadar).
So my question is if the syslog-ng OSE is getting 100K logs/sec then would I able to send those logs to the QRadar system with reduce EPS rate i.e 2500EPS.
I am not sure if I understand you well. How did you plan that to achieve? Drop the 97,5% of the logs based on...? Or does the logs correlate with each other, and in real: 40 log event is about one "real"/ big event, which should be transformed somehow into one? Can you show example about what you would expect? Eg. show 200 incoming log event example, and show the other 5 which should be leave the syslog-ng towards qradar? Kind regards, György Pásztor
participants (3)
-
Muhammad Asim
-
PÁSZTOR György
-
Scheidler, Balázs