The Centrify Infrastructure Services DSM is used for parsing events. This DSM is available with the latest version of QRadar. For an existing QRadar installation, you can get the DSM through an automatic update or by manual installation.
Updates to the DSM, PROTOCOL, and VIS RPMs are made available on a weekly basis to QRadar administrators.
Use the Internet to enable the appliances to connect to an automatic update server:
Log in to the QRadar Console as the admin user.
Go to Admin > Auto Update to see all the available updates.
Choose the appropriate option for your installation.
To manually install the DSM:
Log in to IBM Fix Central and search for the Centrify Infrastructure Services DSM.
Download the RPM file from the location specified in the Introduction section.
Copy this bundle to the QRadar Console.
Log in (SSH) to the QRadar Console and run the following command:
rpm –ivh DSM-CentrifyInfrastructureServices-7.3-20171106211603.noarch
If you do not see the DSM named Centrify Infrastructure Services using the command:
rpm -qa | grep -i Centrify
then download the DSM from the IBM web site.
To install the DSM, add the DSM to the QRadar instance using WInSCP and run the following command:
yum -y install <rpm_filename>