Forum Discussion

Joe's avatar
Joe
Comet
2 months ago

Logs from Azure are encrypted on Qradar

Hello everyone

we are integrating CATO to send events to an azure and from there our SIEM service will collect the logs using Qradar.

The workflow is:

Cato > container > logic app > event hub.

we are getting logs on Qradar but they seem to be encrypted.

when we download the logs from the container to a local PC they are readable.

this is my first attempt with azure integration so i have no idea where too start.. 

Thanks

  • peter's avatar
    peter
    Icon for Cato Employee rankCato Employee

    Hello Joe,

    If those log files have been pushed using our Event Log feature, they will be gzipped.

    • Joe's avatar
      Joe
      Comet

      Hello Peter

      I used "Event Integrations" 

      How can i solve this issue?

    • Joe's avatar
      Joe
      Comet

      Hello Peter

      I used "Event Integrations" 

       

       

      How can i solve this issue?