<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No Malware Events  Seen - eStreamer Integration(FMC &amp;amp;  IBM Qradar)!! in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/no-malware-events-seen-estreamer-integration-fmc-amp-ibm-qradar/m-p/3322724#M4875</link>
    <description>&lt;P&gt;we have a similar problem&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you checked payload for malware traces? In my case i have traced some payloads with malware details etc , but they did not come from intended Log Source (i believe it should come from Log source Firesight)&amp;nbsp; instead from Log source source snort@ firewall name and hence resulting in unknown event.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please update if you have an answer by now&lt;/P&gt;</description>
    <pubDate>Wed, 31 Jan 2018 17:11:09 GMT</pubDate>
    <dc:creator>santhakumar.saseendran</dc:creator>
    <dc:date>2018-01-31T17:11:09Z</dc:date>
    <item>
      <title>No Malware Events  Seen - eStreamer Integration(FMC &amp;  IBM Qradar)!!</title>
      <link>https://community.cisco.com/t5/endpoint-security/no-malware-events-seen-estreamer-integration-fmc-amp-ibm-qradar/m-p/3223051#M4872</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need some assistance&amp;nbsp;to have visibility for Malware events on&amp;nbsp;IBM Qradar, the estreamer integration works fine and I can see events, IPS, Connection logs however I cant see any Malware events.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have tried to generate Malware events for both Network and Endpoint level (AMP VPC is also integrated with FMC) however I am unable to see any Malware logs/events. The connection events does report connection to the site from where I am downloading test Malware samples.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The events are seen on the FMC however the SIEM/IBM Qradar is unable to report any information. Please suggest if we need to do anything additional.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Mar 2019 01:45:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/no-malware-events-seen-estreamer-integration-fmc-amp-ibm-qradar/m-p/3223051#M4872</guid>
      <dc:creator>tushar_bangia</dc:creator>
      <dc:date>2019-03-09T01:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: No Malware Events  Seen - eStreamer Integration(FMC &amp;  IBM Qradar)!!</title>
      <link>https://community.cisco.com/t5/endpoint-security/no-malware-events-seen-estreamer-integration-fmc-amp-ibm-qradar/m-p/3223053#M4873</link>
      <description>&lt;P&gt;I can only find below close matching caveat however the bug lacks information.&lt;/P&gt;
&lt;DIV class="bugTitle"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="bugId"&gt;CSCvc91960 -&amp;nbsp;Streamed Malware events uses the connection event direction&lt;/DIV&gt;
&lt;DIV class="bugId"&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvc91960" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvc91960&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV class="bugId"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 27 Nov 2017 13:18:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/no-malware-events-seen-estreamer-integration-fmc-amp-ibm-qradar/m-p/3223053#M4873</guid>
      <dc:creator>tushar_bangia</dc:creator>
      <dc:date>2017-11-27T13:18:57Z</dc:date>
    </item>
    <item>
      <title>Re: No Malware Events  Seen - eStreamer Integration(FMC &amp;  IBM Qradar)!!</title>
      <link>https://community.cisco.com/t5/endpoint-security/no-malware-events-seen-estreamer-integration-fmc-amp-ibm-qradar/m-p/3224482#M4874</link>
      <description>&lt;P&gt;&lt;BR /&gt;Hello Tushar,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on the info provided, I'd suggest you to contact IBM as well to double check settings and app logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;QRadar is using estreamer FMC API but ultimately it's IBM's app the one generating the data.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd also suggest you&amp;nbsp;should open a case to the FMC team as this is a matter of extensive investigation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards!&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2017 16:43:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/no-malware-events-seen-estreamer-integration-fmc-amp-ibm-qradar/m-p/3224482#M4874</guid>
      <dc:creator>IvanCdC</dc:creator>
      <dc:date>2017-11-29T16:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: No Malware Events  Seen - eStreamer Integration(FMC &amp;  IBM Qradar)!!</title>
      <link>https://community.cisco.com/t5/endpoint-security/no-malware-events-seen-estreamer-integration-fmc-amp-ibm-qradar/m-p/3322724#M4875</link>
      <description>&lt;P&gt;we have a similar problem&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you checked payload for malware traces? In my case i have traced some payloads with malware details etc , but they did not come from intended Log Source (i believe it should come from Log source Firesight)&amp;nbsp; instead from Log source source snort@ firewall name and hence resulting in unknown event.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please update if you have an answer by now&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jan 2018 17:11:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/no-malware-events-seen-estreamer-integration-fmc-amp-ibm-qradar/m-p/3322724#M4875</guid>
      <dc:creator>santhakumar.saseendran</dc:creator>
      <dc:date>2018-01-31T17:11:09Z</dc:date>
    </item>
  </channel>
</rss>

