# Qradar logs to elasticsearch

**URL:** <https://discuss.elastic.co/t/qradar-logs-to-elasticsearch/314853>\
**Category:** Elastic Agent\
**Tags:** integrations\
**Created:** [September 21, 2022, 10:13am UTC](https://discuss.elastic.co/t/qradar-logs-to-elasticsearch/314853 "2022-09-21T10:13:21Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Arslonbek\_Toshev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arslonbek_toshev/32/97526_2.png) [@Arslonbek\_Toshev](https://discuss.elastic.co/u/Arslonbek_Toshev)\
**Post date:** [September 21, 2022, 10:13am UTC](https://discuss.elastic.co/t/qradar-logs-to-elasticsearch/314853/1 "2022-09-21T10:13:21Z")

</div>

We have couple Sophos FWs sending logs to Qradar SIEM which we plan to extend to Elastic for threat hunting (Log Forwarding from Qradar to Elastic). In Integrations I choose Sophos. but logs don't parse correctly. the problem is The syslog header added by the QRadar forwarder, which is not the original header.

Can anybody help me to solve this problem

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 19, 2022, 10:13am UTC](https://discuss.elastic.co/t/qradar-logs-to-elasticsearch/314853/2 "2022-10-19T10:13:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
