It sounds like you've correctly configured the ATP app and log source in QRadar, but the logs are not reaching the SIEM.
Here are a few steps to check:
- Verify that the ATP server is correctly forwarding logs to the QRadar instance.
- Ensure the log source in QRadar is set to receive data from ATP.
- Check network/firewall settings to ensure there's no blockage between ATP and QRadar.
- Review QRadar's logs for any errors related to the log source.
If everything seems correct, try restarting the log source or re-authenticating the connection.
Original Message:
Sent: Sep 17, 2018 07:53 AM
From: 192.168.42.24 192.168.42.24
Subject: ATP integration with IBM Qradar
Dear All,
I trying to connect ATP app to IBM Qradar.
I configure the app, ATP Server XX.XX.XX.XX and Authorization Token: it ok.
I enter the ATP app(on IBM Qradar)
Everything is at 0.
I configure Log source "ATP" Forwarded, And i do not get any logs. to SIEM.
I would be happy to receive an answer, guidance on the matter
(I created events that were opened on ATP Interface)