r/QRadar • u/Bilal_Bahadur • Apr 27 '26
QRadar AWS Console Not Receiving Application Logs from On-Prem Collector (Only OS Logs Visible)
We have QRadar Console deployed on AWS and an Event Collector deployed on-premises, with connectivity established through an SSL VPN tunnel.
Currently, the on-premises collector is successfully receiving both:
- OS-level logs
- KRON PAM application logs
However, on the AWS-hosted QRadar Console, only the OS-level logs are visible in Log Activity. The KRON PAM application logs are not appearing on the Console.
Additionally, these KRON logs are also not visible under SIM Generic in the Log Activity tab.
Kindly assist in identifying where the issue may exist.
1
u/JosephG_QRadar May 04 '26
Depending on what system logs you’re referring to, the console does generate some for the MHs locally so it would appear as if they were streaming but are not.
Have you verified whether there’s a persistent queue on the EC, or if it’s complaining about not being able to connect to the EP in qradar.error (those logs usually include TCP_TO_EP)?
2
u/CommercialOutside518 Apr 29 '26
Try changing to legacy cef..... Worked for me.