---
title: "Setting up IBM QRadar"
canonical: "https://docs.infoblox.com/space/BloxOneCloud/35463741/Setting%20up%20IBM%20QRadar"
format: markdown
---
The **Log Activity** tab in the IBM QRadar console displays real-time information about the data transferred from Data Connector to the console: 

> Macro (inline-media-image)

  
  
**Image**: T<span style="color: #0d0d0d">he IBM QRadar Security Intelligence platform "Log Activity" tab, which displays a table of security events.</span>

When you click a log event, the console will display detailed information about it:  
  
> Macro (inline-media-image)



**Image**: The IBM QRadar Security Intelligence platform displaying a the view of a specific event within the "Log Activity" section of the tool:  


The "Event Information" section includes:

T<span style="color: #0d0d0d">he IBM QRadar Security Intelligence platform "Log Activity" tab, which displays a table of security events.</span>  


If the events are shown as **Unknown** in the QRadar SIEM server, then do the following:

1. Inspect the unknown event’s packet to identify the category name associated with the event.

2. Create an Event Categorization with the category name. This will generate a QID.

3. Map the unknown event to the generated QID. All future events that match these criteria will be mapped to the specified QID.

For details, see [Universal LEEF event map creation](https://www.ibm.com/docs/en/dsm?topic=leef-universal-event-map-creation#c_dsm_guide_universalleef_eventmap) and [Creating an event map and categorization](https://www.ibm.com/docs/en/qsip/7.3.2?topic=mapping-creating-event-map-categorization).

To receive DNS queries and responses from Data Connector, configure a log source on the console:

1. Log in to the console.

2. Open the **Admin** tab, click **Data Sources** > **Events**, and click **Log Sources**.  
  
> Macro (inline-media-image)



  
**Image**: <span style="color: #0d0d0d">The web-based configuration panel for adding a log source within a security event management system</span>  


- The "Event Information" section includes:

3. Click **Add**. The* ***Log Sources** screen will open:  
  
> Macro (inline-media-image)

  
**Image**: The <span style="color: #0d0d0d">configuration interface for adding a log source in a security information.</span>

4. Specify the following:

- **Log Source Name**: Provide a name that does not exceed 256 characters.
- **Log Source Description**: Provide a description that does not exceed 256 characters.
- **Log Source Type**: Select **Universal Leef**. Infoblox supports the Universal Leef Syslog format for IBM QRadar.
- **Protocol Configuration**: To use the TLS encryption protocol for Syslog, select **TLS Syslog**.
- **Log Source Identifier**: Specify the same IP address as the one you specified while configuring the destination in Data Connector.
- **TLS Listen Port:** Specify the same port number as the one you specified while configuring the destination in Data Connector.
- **Authentication Mode**: To use the TLS encryption protocol for authentication, select **TLS**.
- **Certificate Type**: Select **Generate Certificate**. TLS will use the certificate to encrypt and authenticate data transfer.
- **Enabled**: Select this checkbox.
- **Please select any groups you would like this log source to be a member of**: Select the checkbox next to the group to which you want to add the log source.

5. In the **Admin** tab of the console, click **Deploy Changes**:

> Macro (inline-media-image)

  
**<span style="color: #0d0d0d"> Image</span>**<span style="color: #0d0d0d">: T</span><span style="color: #0d0d0d">he IBM QRadar Security Intelligence "Admin" tab displaying the Deploy Changes panel. </span>  
  
6. Click **Save**.

For more information, refer to the *IBM QRadar *document*.*