We want to extend our Qradar to Elastic for threat hunting, so we intend on forwarding logs from Qradar to Elastic via log forwarding, via syslog or via JSON.
Since I cannot install any beats on QRadar Server, will forwarding logs through JSON help in easier parser creation.