cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3344
Views
0
Helpful
1
Replies

Source fire integration with QRADAR

hardeepsinghcs
Level 1
Level 1

Hello. I’m trying to configure sending event logs from Sourcefire DC to IBM Security QRadar SIEM using the eStreamer API Service. There is information from IBM documentation: I must download and install one of the following hotfixes from the Sourcefire website to collect Sourcefire Defense Center 5.x events in QRadar: – Sourcfire_hotfix-v5.1.0-0-build_1.tar – Sourcfire_hotfix-v5.1.1-0-build_1.tar

Could you please tell me where can I find these hotfixes? The second question: I have installed Sourcefire v 5.3.1 (build 152). Is there hotfix for this version?

1 Reply 1

atatistc
Cisco Employee
Cisco Employee

You probably already figure this out...  The hotfixes you're referring to were for the 5.1x version.  Since you're now at 5.3x they would not be needed.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card