Flowmon ADS configuration
- Last Updated: May 1, 2026
- 3 minute read
- Flowmon Products
- Flowmon Anomaly Detection System
- Documentation
After the installation, follow these steps to configure Flowmon ADS:
- Open your Flowmon ADS module and set up Syslog reporting. Find this option in the Processing menu under Event reporting and then Syslog.
- Then, go to your Flowmon Configuration Center module to System > System Settings > Syslog Event Logging.
- Enable Use syslog event logging.
- Click New server.
- Enter the IP address of your QRadar appliance and its port, and select TCP as the protocol.
- Click OK.
- Click Configure syslog message.
- Select the logs you want to send to QRadar. ADS logs are in the SSH Logs group and are the only logs related to the Flowmon ADS Content Pack.
- Click Save.
- After configuring the Syslog messages, click Hostname and take note of the current hostname of your Flowmon because this hostname is used for identification of syslog messages and must be set in QRadar.
- Go to QRadar.
- Select the Admin tab.
- Click Log Sources.
- Click Log Sources.
- Click New Log Source in the top-right corner.
- Click Single Log Source.
- From the list of available log source types, select Flowmon ADS and click Select Protocol Type at the bottom-right.
- Select Syslog from the list of available protocols and click Configure Log Source Parameters at the bottom-right.
- Fill in the protocol source parameters and click Configure Protocol Parameters.
- Fill in the Log Source Identifier (the value must be the same as the value set in the Hostname setup in the Flowmon Configuration Center) and click Finish.
After saving these settings, deploy the new changes and start collecting parsed logs in your QRadar.