Address Manager provides support for IBM® QRadar® and HP® ArcSight® SIEM integration through DNS/DHCP Server syslog to provide more analysis of DNS and DHCP data within an organization.
You can enable syslog redirection on DNS/DHCP Server to IBM QRadar and HP ArcSight servers from the Address Manager user interface.
To enable syslog redirection on DNS/DHCP Server to IBM QRadar and HP ArcSight:
Note: SIEM syslog
messages
Logs being sent to the IBM QRadar and HP
ArcSight servers contain the following:
- DNS queries (querylogging)
- DNS record changes
- DDNS updates being forwarded as DNS_updates
- DHCP logs—logging of the following DHCP packet types: Discover, Offer, Request, Acknowledgement, Negative Acknowledgement, Decline, Inform, and Release