BAM provides support for IBM® QRadar® and HP® ArcSight® SIEM integration through BDDS syslog to provide more analysis of DNS and DHCP data within an organization.
You can enable syslog redirection on BDDS to IBM QRadar and HP ArcSight servers from the BAM user interface.
To enable syslog redirection on BDDS to IBM QRadar and HP ArcSight:
Note: SIEM syslog
messages
Logs being sent to the IBM QRadar and HP
ArcSight servers contain the following:
- DNS queries (querylogging)
- DNS record changes
- DDNS updates being forwarded as DNS_updates
- DHCP logs—logging of the following DHCP packet types: Discover, Offer, Request, Acknowledgement, Negative Acknowledgement, Decline, Inform, and Release