IBM QRadar

IBM QRadar

Join this online topic group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.


#Security
#QRadar
#SecuringhybridcloudandAI
 View Only
  • 1.  Cross-Domain reference sets

    Posted 02/26/20 09:16 AM
    Hi all, 
    We have a multi-tenant Qradar deployment and, in the network hierarchy, I want to have defined the private network ranges to be used in rules for any domain.
    But if I define the network as "Default Domain" then it is only applied to events without specific domain, so the only way I see to have the private nets defined for each domain is creating a different network for each domain with the same network ranges.

    Is there a way to define a network to be used by any domain? 

    Thank you all for your help!

    ------------------------------
    JorgeGar
    ------------------------------


  • 2.  RE: Cross-Domain reference sets

    Posted 02/27/20 06:28 AM
    A little more info around your use of Default Domain would allow a better anwer from myself.

    We have a senario where we have a shared service between domain's such as a resilient internet connection which feeds each domains specific firewall. For our senario we migrated this IP range to a "service" type domain - any offence's raised against this domain is then acted as a customer itself.
    Any IP's (such as athe ones allocated to the domain specific firewall is assigned to the customers network hirarchy itself.



    ------------------------------
    JH
    ------------------------------



  • 3.  RE: Cross-Domain reference sets

    Posted 02/27/20 11:50 AM
    Hi James,

    Thanks for your answer. We have a different domain for each of our clients, so each event has an associated domain, which means none of them has "Default Domain".

    When creating a network I have to assign it either the "Default Domain" or one of the client domains. But the private network ranges are the same for each client, of course, but if I want to use the network "private_ips" in rules and searches, the network seems to need having the same domain that the log source, that is, if a specific log source has domain A, I need to compare the local network of its events towards a network on the same domain, then, to use the "private_ips" network on each of the customers, I need to create a "private_ips" network on each domain, at least I do not see any alternative at this moment.

    Sorry if it is not clear enough, I am afraid my English is quite limited.

    Best Regards,
    Jorge

    ------------------------------
    Jorge García
    ------------------------------