IBM QRadar

Forward Windows logs to IBM QRadar over syslog, with the noise removed first.

DPLens sends Windows Event Log data to a QRadar syslog log source as RFC 5424 syslog or Snare records, over TLS where your listener supports it, and drops what you do not need before it counts against your events per second.

  • RFC 5424 syslog
  • Snare format
  • TLS on 6514
  • Disk cache and failover

In short

DPLens forwards Windows logs to IBM QRadar through QRadar's standard syslog input. Send RFC 5424 syslog over TLS (or Snare records if your QRadar already parses them) from each Windows server, and filter at the source so QRadar spends events per second only on what your rules use.

Which receiver type

Which format should I send to QRadar?

DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. Replacing Snare agents that already feed QRadar? Choose the Snare format, so existing log sources and parsing keep working, and turn on message rendering for the source so the Snare category column is filled. See Snare agent replacement.

New collection, or replacing another agent? Choose RFC 5424 syslog over TLS. Before you roll out, send a test event and confirm with your QRadar administrator that the log source type you plan to use parses it. If that parser expects the Windows message text, turn on message rendering for the source.

NDJSON keeps every field named; choose it where your QRadar team parses JSON on that log source.

Transport

Use TLS to your QRadar syslog listener (6514 is conventional), or TCP on a network you control; both give disk-cached, counted delivery with failover. Match the framing, octet-counted or newline, to what your listener expects; the syslog and Snare guide explains the choice.

DPLens destination settings for QRadar
SettingSuggested valueWhy
TransportTLSEncryption plus a disk cache and failover
AddressYour QRadar collector's TLS syslog port, usually 6514Point it at the event collector that owns the log source
FailoverA second collectorDPLens moves back once the first is healthy again
FormatRFC 5424 syslog or SnareWhatever your log source parses
CA certificateThe CA that issued the listener's certificateDPLens validates the listener's certificate
HostnameThis machine's name (the default)QRadar tells hosts apart by the header
Facility13 (log audit)A common choice for security data

On the QRadar side

What QRadar needs

  • A log source, or a listener with auto-detected log sources, that accepts syslog on the protocol and port you chose. For TLS, QRadar's TLS syslog listener and a certificate DPLens can validate.
  • A DSM that parses Windows events in the format you send. QRadar's Microsoft Windows Security Event Log DSM is the usual one; check with your administrator which event formats your version accepts.
  • A way to tell hosts apart. QRadar commonly identifies a syslog log source by the hostname or address in the message header, and DPLens writes each machine's own name there by default.
  • Firewall rules from each Windows server to the collector on the chosen port.

Cutting EPS

Spend QRadar's events per second on what your rules use

QRadar capacity is commonly sized and licensed by events per second, so every event you do not send is headroom. Every drop DPLens makes is counted and attributed to the rule that made it; SIEM cost reduction covers the techniques.

01

Exclude at the source

An Event ID excluded on the Windows Event Log source is never read. Use this for IDs no rule uses, such as high-volume Windows Filtering Platform events (5156, 5158) where you do not alert on them.

02

Drop machine accounts

A pipeline filter can keep a list of Event IDs and drop those whose target account ends in $.

03

Collapse failures

Aggregate failed logons (4625) by user and source address over 60 seconds into one event carrying the count. Check that your brute-force rules can read the count first.

Before dropping anything, check it against your offenses and rules. See the noisiest Windows Security Event IDs.

Rolling out

Configure once, deploy to every Windows server

DPLens Manager, included in every subscription, gives you central configuration, fleet health monitoring, and deployment and upgrades for every agent that feeds QRadar. It is self-hosted and air-gap capable.

Secure by design

An agent you can defend in a security review.

Signed and verifiableEvery release is signed and ships with checksums and a software bill of materials, so you can verify it before it reaches a server.
Nothing calls homeNo telemetry, no licence server and no automatic updates. Your data goes only where you send it.
Secure engineeringBuilt and tested to modern secure-development practice, for software that runs on your most sensitive servers.
Least privilegeRuns with only the access it needs, with administration kept apart from collection.

FAQ

Questions QRadar teams ask

How does DPLens connect to QRadar?

Through QRadar's own syslog inputs. DPLens sends standard RFC 5424 syslog or Snare records to a log source you configure, and QRadar parses them with the log source type you choose.

Can DPLens replace WinCollect?

DPLens forwards the same Windows event channels as syslog from each machine it is installed on. Confirm your log source type parses what it sends, run both side by side, then decommission the old collection.

What happens if the QRadar collector is down?

On TCP or TLS, events queue in the destination's disk cache (sized per destination) and are delivered when it returns, or DPLens moves to a failover collector. If the cache fills, your chosen policy applies and every drop is counted.

IBM and QRadar are trademarks of their respective owners. DPLens is not affiliated with or endorsed by them. The names are used here only to say what DPLens interoperates with.

See it on your own logs

Try DPLens on one Windows server before you talk to anyone.

Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.