Verification
After completing the setup and configuration, it's important to verify that QRadar is receiving and correctly parsing logs from Secret Server.
-
In QRadar, go to Log Activity.
-
Filter by Log Source: Secret Server.
-
Check for events like:
-
Login Success/Failure
-
Secret Access
-
Password Rotations
-
Session Start/Stop
-