Hello Benjamin,
Just a bit of a warning here.
HA support is between two appliances only. If physical appliances they need 100Mb LAN between them and RTT if not in the same rack is 2-5millisconds. Depending on the appliance, you will need OS bit-wise replication in place, which is usually a fibre connection (if you have physical appliances). For virtual appliances, the same SLAs apply.
HA of appliances between sites is not supported. If you try this, you are on your own without support.
Despite asking for this to be clearly documented by IBM over the last two years, HA is to support HA of the hardware only. It is not HA for the software - do ask your IBM rep to confirm this so you have an audit trail.
Timings for HA ... if you do via the UI, HA takes between 2 and 5 minutes for active/standby to change state.
For an HA appliance doing ingest, all traffic is dropped when fail-over happens. Uncontrolled fail-over (pulling the power on an active appliance) is a bit faster but still takes a few minutes.
In summary, HA-support it is not a great product and the problems with it are not public nor obvious.
If you need multi-site, look at the DR application and the data replication license would be needed. Although the DR app is a new product - caveat emptor.
There are some thoughts of using VMWare site-replication to provide more DR-like capability, but that is another topic and has different issues.
Kind regards,
------------------------------
Darren H.
------------------------------
Original Message:
Sent: Sun December 13, 2020 01:46 AM
From: benjamin Nworah
Subject: HA Implementation between two sites
Hello QRadar experts,
I want to implement HA in two different sites. One at my Production site, and the other at DR.
What are the steps required to set this up?
- What latency should i consider?
- What bandwith can i use to achieve this? the distance between sites are 1.5km
- Where will the HA activation key be applied, Secondary or Primary?
- If set up, when the primary fails, how does the VIP moves to the secondary?
- when the primary fails, how does the log sources send traffic to the secondary? should i set up network connectivity between log sources and secondary appliance?
Thanks Expert, i want to hear from you
------------------------------
benjamin Nworah
------------------------------