Past workJr. Security Engineer, SOCByte, 2026.

QRadar audit: parsing for 50+ assets and coverage for 190 more

A SIEM audit for a microfinance bank. Corrected parsers and DSM/event mappings that sent 50+ assets into SIM Generic (unknown/unparsed events down 80%), and integrated 190 previously unmonitored assets.

  • 80%Unknown/unparsed eventsreduction after correcting parsers and mappings
  • 50+Assetsmoved out of SIM Generic with corrected parsing
  • 190Unintegrated assetsidentified and brought into monitoring

These are separate results from the same audit. They are not added together.

QRadar audit: parsing for 50+ assets and coverage for 190 more

Context

I led a SIEM audit for a microfinance bank. Two problems surfaced: events from many assets were arriving but not being understood, and a large set of assets was not sending anything at all.

Why an unparsed event is a monitoring gap

When a parser matches

  1. Raw event arrives
  2. DSM parses fields
  3. Event mapped to a category
  4. Usable by rules, offenses, searches, reports

When nothing matches

  1. Raw event arrives
  2. No matching parser
  3. Lands under a generic, unknown category
  4. Stored, but effectively invisible to analysis
Explanatory view of the QRadar event path. Not specific to any client.

Parsing and normalization

Traffic from more than 50 assets was landing in SIM Generic, QRadar’s fallback when no specific parser handles a source. Those events are stored, but without proper parsing and categorisation, rules, offenses, and reports cannot use them reliably.

I corrected the log source parsers and DSM/event mappings for those assets. Unknown and unparsed events dropped by 80%, and accurate normalization was restored for rule, offense, and reporting coverage.

Coverage

In the same environment I identified 190 assets that were not integrated with the SIEM, and remediated their log source integrations so they forward the relevant event IDs. Systems that had been invisible to monitoring came into active coverage.

Why this matters

Monitoring is only as good as the data under it. A correct alert logic can still miss everything if the events it depends on are unparsed, mis-categorised, or never sent. This kind of work is unglamorous and it is where coverage is actually won or lost.

Search the site