Network Management

Configure SolarWinds Orion to send information to QRadar

Forward information from SolarWinds alerting to QRadar

First published date

1/20/2020 8:10 PM

Last published date

9/18/2023 7:49 AM

Overview

This article will provide a step by step guide on how to create an alert action to forward information to QRadar.

Product section

Network Performance Monitor

Resolution

  1. Open Orion Web Console
  2. Navigate to Settings > All Settings > Manage Alerts
  3. Select or create an alert you wish to forward information to QRadar and an existing alert and then click ADD NEW ALERT/ EDIT ALERT
  4. Navigate to the Triggered Actions tab
  5. Click Add New Action
  6. In the Select an Action window, select Send an SNMP Trap and then click OK.
  7. Set the values for destination (IP of QRadar Console or QRadar Event Collector)
  8. Select Trap template (if the information is not in the format you wish to receive it in QRadar you can use the following documentation to edit or create your own template: What is a Trap Template?) For most configurations ForwardSyslog
  9. Configure the SNMP Properties:
    1. Enter a UDP Port number in the field provided
    2. Select an SNMP Version from the drop-down list
    3. Enter the SNMP Community String in the field provided
  10. To verify that your SNMP trap is configured properly, select an alert that you edited and click Test. This action triggers and forwards the events to QRadar
  11. Click SAVE CHANGES
  12. Click Next
  13. Next to the Summary page
  14. Click Submit
Note: Repeat these steps to configure the SolarWinds Orion Alert Manager with all of the SNMP trap alerts that you want to monitor in QRadar.

Other resources:
Please take note that we can only send SNMP trap to QRadar, as is described in this article: