Powered by Zoomin Software. For more details please contactZoomin

Flowmon ADS Content Pack User Guide

Flowmon ADS configuration

  • Last Updated: May 1, 2026
  • 3 minute read
    • Flowmon Products
    • Flowmon Anomaly Detection System
    • Documentation

After the installation, follow these steps to configure Flowmon ADS:

  1. Open your Flowmon ADS module and set up Syslog reporting. Find this option in the Processing menu under Event reporting and then Syslog.
Syslog reporting configuration screen
Syslog reporting configuration screen

  1. Then, go to your Flowmon Configuration Center module to System > System Settings > Syslog Event Logging.
  2. Enable Use syslog event logging.
  3. Click New server.
New server button in Syslog settings
New server button in Syslog settings

  1. Enter the IP address of your QRadar appliance and its port, and select TCP as the protocol.
  2. Click OK.
  3. Click Configure syslog message.
Configure syslog message button
Configure syslog message button

  1. Select the logs you want to send to QRadar. ADS logs are in the SSH Logs group and are the only logs related to the Flowmon ADS Content Pack.
SSH Logs selection screen
SSH Logs selection screen

  1. Click Save.
Save button for syslog configuration
Save button for syslog configuration

  1. After configuring the Syslog messages, click Hostname and take note of the current hostname of your Flowmon because this hostname is used for identification of syslog messages and must be set in QRadar.
  2. Go to QRadar.
  3. Select the Admin tab.
QRadar Admin tab
QRadar Admin tab

  1. Click Log Sources.
Log Sources menu item
Log Sources menu item

  1. Click Log Sources.
Log Sources menu item
Log Sources menu item

  1. Click New Log Source in the top-right corner.
New Log Source button
New Log Source button

  1. Click Single Log Source.
Single Log Source option
Single Log Source option

  1. From the list of available log source types, select Flowmon ADS and click Select Protocol Type at the bottom-right.
Select Protocol Type button
Select Protocol Type button

  1. Select Syslog from the list of available protocols and click Configure Log Source Parameters at the bottom-right.
Configure Log Source Parameters button
Configure Log Source Parameters button

  1. Fill in the protocol source parameters and click Configure Protocol Parameters.
Configure Protocol Parameters button
Configure Protocol Parameters button

  1. Fill in the Log Source Identifier (the value must be the same as the value set in the Hostname setup in the Flowmon Configuration Center) and click Finish.

After saving these settings, deploy the new changes and start collecting parsed logs in your QRadar.

TitleResults for “How to create a CRG?”Also Available inAlert