Start a Conversation

Unsolved

JK

1 Rookie

 • 

1 Message

173

October 2nd, 2023 12:22

SMB Auditing

Good Morning,  I would like to forward Unity 480 NAS SMB auditing to IBM QRadar.   I am having difficultly find the correct process.   Is there documentation specify for the Unity NAS and QRadar for SMB Auditing?    Thank you for your time!

Moderator

 • 

7.5K Posts

October 2nd, 2023 21:31

Hello James Karch,

There is no documentation for forwarding Unity NAS SMB to QRadar for auditing. Here is the link to the Dell Unity Family Security Configuration Guide, and if you look on page 26 it talks about remote logging.

https://dell.to/3S0nQNZ

3 Apprentice

 • 

318 Posts

October 11th, 2023 17:49

are you sure this is supported in QRadar ? Is this the type of thing you are looking to do ? https://www.varonis.com/integrations/dell-emc

3 Apprentice

 • 

318 Posts

October 11th, 2023 17:53

see https://www.dell.com/support/kbdoc/en-us/000019572/unity-dell-emc-unity-cee-cepa-user-correctable?lang=en

7 Posts

October 24th, 2023 12:04

Hello James , exactly i have the same problem so noboy replies it correctly as far as i can see.  But i did a lot of work on this problem and as i find out you need to install CEE to a server  than you also need to install the Qradar agent  eg.  Wincollect to the same CEE server than you may change some registery settings to enable it to forward the logs to wincollect agent.     I find those 2 links for 2 different products and its showing exactly how to do this but for the qradar wincollect agent  , i couldnt find the endpoint name to use at registery to enable it.  So if you can find any way to solve it please can you share with me ?  

On the other hand there is syslog logging which you may find under settings at unity management tab for remote logging  , but i am not sure if it will show nas server file change audits or not..  

1 -https://helpcenter.netwrix.com/bundle/StealthAUDIT_11.5/page/Content/Configuration/EMC_Unity_Config/Activity_Monitor_Configuration.htm

2 - https://community.sailpoint.com/mpomh84452/attachments/mpomh84452/SIQ_docs/363/3/Integrating%20EMC%C2%A0Unity%20CIFS%20with%20File%20Access%20Manager.pdf

1 Rookie

 • 

1 Message

May 6th, 2024 07:02

@geometry dash scratch Thanks for sharing. It's useful for me. 

(edited)

No Events found!

Top