Network Management
Configure SolarWinds Orion to send information to QRadar
Forward information from SolarWinds alerting to QRadar
First published date
Last published date
Overview
Product section
Resolution
- Open Orion Web Console
- Navigate to Settings > All Settings > Manage Alerts
- Select or create an alert you wish to forward information to QRadar and an existing alert and then click ADD NEW ALERT/ EDIT ALERT
- Navigate to the Triggered Actions tab
- Click Add New Action
- In the Select an Action window, select Send an SNMP Trap and then click OK.
- Set the values for destination (IP of QRadar Console or QRadar Event Collector)
- Select Trap template (if the information is not in the format you wish to receive it in QRadar you can use the following documentation to edit or create your own template: What is a Trap Template?) For most configurations ForwardSyslog
- Configure the SNMP Properties:
- Enter a UDP Port number in the field provided
- Select an SNMP Version from the drop-down list
- Enter the SNMP Community String in the field provided
- To verify that your SNMP trap is configured properly, select an alert that you edited and click Test. This action triggers and forwards the events to QRadar
- Click SAVE CHANGES
- Click Next
- Next to the Summary page
- Click Submit
Other resources:
- Configuring SolarWinds Orion to communicate with QRadar (© 1994 - 2022 IBM Corporation, available at https://www.ibm.com, obtained on February 01, 2022)