Skip to content

Commit 38519d1

Browse files
authored
Merge pull request #207684 from batamig/patch-230
adding sample payload sent to qradar
2 parents 405b8de + 198e0b9 commit 38519d1

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

articles/defender-for-iot/organizations/tutorial-qradar.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -109,6 +109,12 @@ For the integration to work, you will need to setup in the Defender for IoT appl
109109

110110
1. Select **Save**.
111111

112+
The following is an example of a payload sent to QRadar:
113+
114+
```sample payload
115+
<9>May 5 12:29:23 sensor_Agent LEEF:1.0|CyberX|CyberX platform|2.5.0|CyberX platform Alert|devTime=May 05 2019 15:28:54 devTimeFormat=MMM dd yyyy HH:mm:ss sev=2 cat=XSense Alerts title=Device is Suspected to be Disconnected (Unresponsive) score=81 reporter=192.168.219.50 rta=0 alertId=6 engine=Operational senderName=sensor Agent UUID=5-1557059334000 site=Site zone=Zone actions=handle dst=192.168.2.2 dstName=192.168.2.2 msg=Device 192.168.2.2 is suspected to be disconnected (unresponsive).
116+
```
117+
112118
## Map notifications to QRadar
113119

114120
The rule must then be mapped on the on-premises management console.

0 commit comments

Comments
 (0)