Hello Everyone,
My team is working on integrating Crowdstrike (CS) with IBM QRadar (QR) using CS App. We are new to IBM QR technology, however, managed to install the App and added the client. However, we don't see any events at "Log Activity" when filtered with "Crowdstrike Detection" data source.
FYI, our setup is running with distributed topology and is multi-tenant.
Following are the issues at hand that we looking for a resolution :
1. Why there no events when from app.log file can see App was successfully able to fetch data stream from CS.
2. How to manage the App in a multi-tenant environment - let's say if more than one of my customers are using CS then how to segregate the traffic among them.
Any response with your past successful experiences will be of immense help.
Thanks
Sai
------------------------------
Sai Kumar
------------------------------