Events Unknown
Problem: Illumio App events are shown as unknown in QRadar.
Use the following steps to troubleshoot:
Go to Log Activity and set Filter Log Source Type to Illumio ASP V2.
In Views, select Last 7 Days.
If any events show as unknown, do the following:
Right-click on the event and select View in DSM Editor.
Under Log Activity Preview, check the value of Event ID and Event Category.
If Event ID and Event Category are unknown, create a support ticket with Illumio.
If the Event ID and Event Category values are not unknown but Event Name is unknown, then add a new event mapping using the following steps:
Navigate to the Event Mapping tab and click Add.
Click Choose QID.
Click Create New QID Record and enter an appropriate name in the Name field.
Select relevant values for the High Level Category and Low Level Category fields.
Click Save and then click OK.
Click Create.