QRadar audit: parsing for 50+ assets and coverage for 190 more
Context
I led a SIEM audit for a microfinance bank. Two problems surfaced: events from many assets were arriving but not being understood, and a large set of assets was not sending anything at all.
Why an unparsed event is a monitoring gap
When a parser matches
- Raw event arrives
- DSM parses fields
- Event mapped to a category
- Usable by rules, offenses, searches, reports
When nothing matches
- Raw event arrives
- No matching parser
- Lands under a generic, unknown category
- Stored, but effectively invisible to analysis
Parsing and normalization
Traffic from more than 50 assets was landing in SIM Generic, QRadar’s fallback when no specific parser handles a source. Those events are stored, but without proper parsing and categorisation, rules, offenses, and reports cannot use them reliably.
I corrected the log source parsers and DSM/event mappings for those assets. Unknown and unparsed events dropped by 80%, and accurate normalization was restored for rule, offense, and reporting coverage.
Coverage
In the same environment I identified 190 assets that were not integrated with the SIEM, and remediated their log source integrations so they forward the relevant event IDs. Systems that had been invisible to monitoring came into active coverage.
Why this matters
Monitoring is only as good as the data under it. A correct alert logic can still miss everything if the events it depends on are unparsed, mis-categorised, or never sent. This kind of work is unglamorous and it is where coverage is actually won or lost.