Digital Developer Conference: a FREE half-day online conference focused on AI & Cloud – North America: Nov 2 – India: Nov 9 – Europe: Nov 14 – Asia Nov 23 Register now

Close outline
  • United States
IBM?
  • Site map
IBM?
  • Marketplace

  • Close
    Search
  • Sign in
    • Sign in
    • Register
  • IBM Navigation
IBM Developer Answers
  • Spaces
    • Blockchain
    • IBM Cloud platform
    • Internet of Things
    • Predictive Analytics
    • Watson
    • See all spaces
  • Tags
  • Users
  • Badges
  • FAQ
  • Help
Close

Name

Community

  • Learn
  • Develop
  • Connect

Discover IBM

  • ConnectMarketplace
  • Products
  • Services
  • Industries
  • Careers
  • Partners
  • Support
10.190.13.195

Refine your search by using the following advanced search options.

Criteria Usage
Questions with keyword1 or keyword2 keyword1 keyword2
Questions with a mandatory word, e.g. keyword2 keyword1 +keyword2
Questions excluding a word, e.g. keyword2 keyword1 -keyword2
Questions with keyword(s) and a specific tag keyword1 [tag1]
Questions with keyword(s) and either of two or more specific tags keyword1 [tag1] [tag2]
To search for all posts by a user or all posts with a specific tag, start typing and choose from the suggestion list. Do not use a plus or minus sign with a tag, e.g., +[tag1].
  • Ask a question

Custom JDBC Query For Microsoft WSUS

504DX0XYB2 gravatar image
Question by Vova Mutsmakher  (1) | Nov 26, 2017 at 05:13 AM qradarjdbccustomquerymicrosoft

Hello,

it looks like the microsoft WSUS is not supported as log source

my customer want to integrate this to Qradar

i know that other SIEM vendors are supports WSUS integartion

i want to know how use already know query (custom for Qradar) for Microsoft WSUS DB in Qradar

thanks

vova@trustnet.co.il

People who like this

  0
Comment
10 |3000 characters needed characters left characters exceeded
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster

1 reply

  • Sort: 
100000NV9W gravatar image

Answer by zoldax (2014) | Nov 26, 2017 at 08:22 AM

Hello Vova,

Some ideas to share with you. Hope this help.

Windows Server Update Services (WSUS) enables information technology administrators to deploy the latest Microsoft product updates. WSUS fully manage the distribution of updates that are released through Microsoft Update to computers.

Windows Server 2008 and 2012 includes WSUS as a role/feature, and you can see a lot of things with it, such as subscribed update categories, download updates status, registered clients to the server, updates agents deployed, IIS logs from WSUS... But you can check also a lot of things on system side too...

You have to check what the Customer want to see with the WSUS role with the SIEM (security operational or security correlation ?)

Some ideas :

Wincollect agent software

First of all, maybe you can use the "Qradar Wincollect" agent on your server containing the WSUS role. It will allow you to collect informations such as : Application, Security, System, Sysinternals Sysmon, DHCP, DNS, File Forwarder, IAS, IIS, ISA, SQLServer, XPath...

Ref : http://public.dhe.ibm.com/software/security/products/qradar/documents/iTeam_addendum/b_wincollect.pdf http://www-01.ibm.com/support/docview.wss?uid=swg27049809

Microsoft security Event Log

If you don't want to use Wincollect (and want to stay agentless) you can use the MSRPC Log (The Microsoft Security Event Log) wich only supports standard Windows event logs for workstations and servers. This allows you to collect Security, System, Application, DNS Server, File Replication, and Directory Service event . But MSRPC is not capable of retrieving or parsing non-Standard windows logs, such as Microsoft IIS, Microsoft SQL. If you require events from any of these systems,you better have to install the WinCollect agent software.

Ref : http://www-01.ibm.com/support/docview.wss?uid=swg21700170

Operational Idea If you use QVM too, you can also fil in the information of email of the technical guys from WSUS Customer in the Assets or Group of Assets, to inform them with a profile type of the critical vulnerabilities they have to manage.

Hope this give you some ideas.

Comment

People who like this

  0   Share
10 |3000 characters needed characters left characters exceeded
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster

Follow this question

134 people are following this question.

Answers

Answers & comments

Related questions

Wincollect / SMB issues Qradar 7.3.0 5 Answers

Installing QRadar Microsoft Event Hub Protocol 1 Answer

Help required in searching the actual source IP where i have the source as DNS server IP 0 Answers

Hardcoded devicetypeid doesn't work with other application with same devicetypeid? 0 Answers

How to query WinCollect agents from QRadar command line 5 Answers

  • Contact
  • Privacy
  • IBM Developer Terms of use
  • Accessibility
  • Report Abuse
  • Cookie Preferences

Powered by AnswerHub

Authentication check. Please ignore.
  • Anonymous
  • Sign in
  • Create
  • Ask a question
  • Spaces
  • API Connect
  • Analytic Hybrid Cloud Core
  • Application Performance Management
  • Appsecdev
  • BPM
  • Blockchain
  • Business Transaction Intelligence
  • CAPI
  • CAPI SNAP
  • CICS
  • Cloud Analytics
  • Cloud Automation
  • Cloud Object Storage
  • Cloud marketplace
  • Collaboration
  • Content Services (ECM)
  • Continuous Testing
  • Courses
  • Customer Experience Analytics
  • DB2 LUW
  • Data and AI
  • DataPower
  • Decision Optimization
  • DevOps Build
  • DevOps Services
  • Developers IBM MX
  • Digital Commerce
  • Digital Experience
  • Finance
  • Global Entrepreneur Program
  • Hadoop
  • Hybrid Cloud Core
  • Hyper Protect
  • IBM Cloud platform
  • IBM Design
  • IBM Forms Experience Builder
  • IBM Maximo Developer
  • IBM StoredIQ
  • IBM StoredIQ-Cartridges
  • IIDR
  • ITOA
  • InformationServer
  • Integration Bus
  • Internet of Things
  • Kenexa
  • Linux on Power
  • LinuxONE
  • MDM
  • Mainframe
  • Messaging
  • Node.js
  • ODM
  • Open
  • PartnerWorld Developer Support
  • PowerAI
  • PowerVC
  • Predictive Analytics
  • Product Insights
  • PureData for Analytics
  • Push
  • QRadar App Development
  • Run Book Automation
  • Search Insights
  • Security Core
  • Storage
  • Storage Core
  • Streamsdev
  • Supply Chain Business Network
  • Supply Chain Insights
  • Swift
  • UBX Capture
  • Universal Behavior Exchange
  • UrbanCode
  • WASdev
  • WSRR
  • Watson
  • Watson Campaign Automation
  • Watson Content Hub
  • Watson Marketing Insights
  • dW Answers Help
  • dW Premium
  • developerWorks Sandbox
  • developerWorks Team
  • Watson Health
  • More
  • Tags
  • Questions
  • Users
  • Badges