Hi,
we're planning on using Logstash as a central shippier to send logs to a SIEM (qradar in this case) & Logstash.
Qradar however doesn't want to automatically parse these events as it doesn't recognize the source (it sees the logstash as the source instead of the original source).
Some possibility's to check is to use the CEF or LEEF plugin.
However, our server doesn't have internet connection nore a local ruby environment to build the gem. This seems to be required.
Can someone build the gem for the LEEF & CEF plugins?
LEEF:https://github.com/avwsolutions/logstash-codec-leef
CEF: https://www.elastic.co/guide/en/logstash/current/plugins-codecs-cef.html
If any other solutions to fix this, feel free to share!
Thanks,
Christiaan