IBM QRadar
Forward Windows logs to IBM QRadar over syslog, with the noise removed first.
DPLens sends Windows Event Log data to a QRadar syslog log source as RFC 5424 syslog or Snare records, over TLS where your listener supports it, and drops what you do not need before it counts against your events per second.
- RFC 5424 syslog
- Snare format
- TLS on 6514
- Disk cache and failover
In short
DPLens forwards Windows logs to IBM QRadar through QRadar's standard syslog input. Send RFC 5424 syslog over TLS (or Snare records if your QRadar already parses them) from each Windows server, and filter at the source so QRadar spends events per second only on what your rules use.
Which receiver type
Which format should I send to QRadar?
DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. Replacing Snare agents that already feed QRadar? Choose the Snare format, so existing log sources and parsing keep working, and turn on message rendering for the source so the Snare category column is filled. See Snare agent replacement.
New collection, or replacing another agent? Choose RFC 5424 syslog over TLS. Before you roll out, send a test event and confirm with your QRadar administrator that the log source type you plan to use parses it. If that parser expects the Windows message text, turn on message rendering for the source.
NDJSON keeps every field named; choose it where your QRadar team parses JSON on that log source.
Transport
Use TLS to your QRadar syslog listener (6514 is conventional), or TCP on a network you control; both give disk-cached, counted delivery with failover. Match the framing, octet-counted or newline, to what your listener expects; the syslog and Snare guide explains the choice.
| Setting | Suggested value | Why |
|---|---|---|
| Transport | TLS | Encryption plus a disk cache and failover |
| Address | Your QRadar collector's TLS syslog port, usually 6514 | Point it at the event collector that owns the log source |
| Failover | A second collector | DPLens moves back once the first is healthy again |
| Format | RFC 5424 syslog or Snare | Whatever your log source parses |
| CA certificate | The CA that issued the listener's certificate | DPLens validates the listener's certificate |
| Hostname | This machine's name (the default) | QRadar tells hosts apart by the header |
| Facility | 13 (log audit) | A common choice for security data |
On the QRadar side
What QRadar needs
- A log source, or a listener with auto-detected log sources, that accepts syslog on the protocol and port you chose. For TLS, QRadar's TLS syslog listener and a certificate DPLens can validate.
- A DSM that parses Windows events in the format you send. QRadar's Microsoft Windows Security Event Log DSM is the usual one; check with your administrator which event formats your version accepts.
- A way to tell hosts apart. QRadar commonly identifies a syslog log source by the hostname or address in the message header, and DPLens writes each machine's own name there by default.
- Firewall rules from each Windows server to the collector on the chosen port.
Cutting EPS
Spend QRadar's events per second on what your rules use
QRadar capacity is commonly sized and licensed by events per second, so every event you do not send is headroom. Every drop DPLens makes is counted and attributed to the rule that made it; SIEM cost reduction covers the techniques.
01
Exclude at the source
An Event ID excluded on the Windows Event Log source is never read. Use this for IDs no rule uses, such as high-volume Windows Filtering Platform events (5156, 5158) where you do not alert on them.
02
Drop machine accounts
A pipeline filter can keep a list of Event IDs and drop those whose target account ends in $.
03
Collapse failures
Aggregate failed logons (4625) by user and source address over 60 seconds into one event carrying the count. Check that your brute-force rules can read the count first.
Before dropping anything, check it against your offenses and rules. See the noisiest Windows Security Event IDs.
Rolling out
Configure once, deploy to every Windows server
DPLens Manager, included in every subscription, gives you central configuration, fleet health monitoring, and deployment and upgrades for every agent that feeds QRadar. It is self-hosted and air-gap capable.
Secure by design
An agent you can defend in a security review.
FAQ
Questions QRadar teams ask
How does DPLens connect to QRadar?
Through QRadar's own syslog inputs. DPLens sends standard RFC 5424 syslog or Snare records to a log source you configure, and QRadar parses them with the log source type you choose.
Can DPLens replace WinCollect?
DPLens forwards the same Windows event channels as syslog from each machine it is installed on. Confirm your log source type parses what it sends, run both side by side, then decommission the old collection.
What happens if the QRadar collector is down?
On TCP or TLS, events queue in the destination's disk cache (sized per destination) and are delivered when it returns, or DPLens moves to a failover collector. If the cache fills, your chosen policy applies and every drop is counted.
See it on your own logs
Try DPLens on one Windows server before you talk to anyone.
Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.