Collecting logs from Siemens SIMATIC PCS 7 and sending them to IBM QRadar could be a complex task because of the unique combination of the log source and the desired destination. This post seeks to explain how to forward log data from SIMATIC PCS 7 to IBM QRadar by incorporating the NXLog log collection tool.
Siemens SIMATIC PCS 7 is a distributed control system (DCS) solution that uses a large number of Siemens hardware components supported and configured by PCS 7 software tools. Deployments usually consist of Engineering stations (ES), Operating Stations (OS), and Automation stations (AS). The PCS 7 AS comprises the Siemens SIMATIC S7-400 series central processing unit, typical use of which is the automation of plants that require a large number of I/O signals and control loops. SIMATIC PCS 7 is commonly used for various automation tasks in industrial sectors such as chemicals, petrochemicals, water treatment, pharmaceuticals and power generation.
SCADA systems and Siemens share a couple of things in common: they employ a variety of network protocols to facilitate communication between various type of nodes (physical computers, CPUs, distributed I/Os, as well as field devices) and SCADA for storing data. Consequently, both solutions are firmly integrated within the corporate networks where those nodes are deployed.
SIMATIC PCS 7 produces a wide variety of logs about its operation. Some of the logs are available through Windows Event Log, but most of the logs are stored as flat files.
Because of the nature and size of the systems controlled by Siemens SIMATIC PCS 7, continuous and safe operation is a must with no room for errors or trade-offs. The logs produced by SIMATIC PCS 7 can provide crucial information about the operation of the entire system it controls. However, the inconsistent formatting and the noisiness of the logs could present some challenges.
NXLog Enterprise Edition is a lightweight, modular log collection tool, capable of tackling the most demanding cases log collection may pose. It possesses a wide range of features that enable it to parse almost any format to produce structured data for further processing. For these reasons, it is the perfect tool for monitoring and collecting SIMATIC PCS 7 logs.
- Collecting SIMATIC PCS 7 logs from Windows Event Log
Windows Event Log is the main log aggregation framework for the Windows platform. The logs created by SIMATIC PCS 7 contain PC station, NET configuration, and adapter operation related information, as well as information about various other services.
- Collecting SIMATIC PCS 7 logs from file
File-based PCS7 logs include WinCC system diagnostics logs, SQL Server logs of WinCC, OS project logs, AS project logs, Multiproject logs as well as Batch logs coming from Automation, Engineering, and Operator stations.
The easiest way to collect and normalize Siemens SIMATIC PCS 7 log data is to collect them with NXLog. With its unique capabilities, logs can be collected from literally any file, in any format. Given the wide variation in format and structure of such log files, its versatility is ideally suited for these systems.
For more information on how to integrate NXLog with SIMATIC PCS 7, you can find detailed documentation here.
The above mentioned log sources, and the features NXLog provides all play an important role when normalizing logs in order to be accepted by QRadar.
IBM QRadar is a Security Information and Event Management (SIEM) system, which accepts log data for further analysis, correlation, and threat intelligence. Its primary role is to identify known or potential threats, provide alerting and reports, as well as aid incident investigations.
To enable logs to be accepted by QRadar from NXLog you must set up your appliance with the appropriate log source in the QRadar web interface. This can by done simply by navigating from the menu to data sources, events and then finally log sources. Here, you can set a log source that is either specific or generic.
- Generic structured logs
Setting up a generic log source in IBM QRadar is important if you wish to send logs from a source that is not among QRadar’s list of predefined log sources.This can be achieved by sending logs to QRadar using the LEEF (Log Event Extended Format).
- Specific log types
IBM QRadar provides a long list of predefined log sources that it can accept, such as those collected by Windows Event Log: DHCP server logs, DNS debug logs, Microsoft Exchange Server logs as well as Microsoft SQL logs, just to name a few.
Forwarding logs to IBM QRadar is straightforward with NXLog since it can connect to IBM QRadar via TCP or establish a secure TLS/SSL connection if security is a concern.