IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Merging two QRadar AIO

    Posted Mon March 09, 2020 06:39 AM
    We have the following setup:
    1. QRadar AIO 1 for Company 1 (Smaller Company)
    2. QRadar AIO 2 for Company 2

    Now both the companies have merged and we are planning to combine QRadars'. We have decided to make QRadar AIO 1 as an event Processor and in the meantime point all logs to QRadar AIO 2. After that we will setup QRadar EP to point to QRadar AIO 2. Can someone check the sanity of this plan and any details on how this can be accomplished will be welcomed.

    ------------------------------
    Muhammad Ausaf Ali Yousaf
    ------------------------------


  • 2.  RE: Merging two QRadar AIO

    Posted Mon March 09, 2020 11:48 AM

    Intresting senario you have, 
    From a going forward point - I can see your way working but wouldnt it cause an issue of a log source on AIO1 and AIO2 exisiting. The cutover point being the date that AIO1 "log sources" stop?

    From a historic point of view wouldnt your previous log source data be at risk because its standalone on AIO1 and the EP on AIO2 not knowing about it?

    I would expect more heavy lifting involving backups from both systems and gluing them togeather somehow and re-importing to a new coverged system. 


    Intrested to see what more experienced people comeup with.



    ------------------------------
    JH
    ------------------------------



  • 3.  RE: Merging two QRadar AIO

    Posted Tue March 10, 2020 06:18 AM
    Edited by Oliver Braun Tue March 10, 2020 06:19 AM
    Hi, 

    I'm a fan of keep it simple. Basically, this is what I would do:

    Preparation
    • which QRadar version should have the common depolyment?
    • agree with IBM that the licenses. (EPS / FPM / Datastore?) can be transferred from AIO1 to the AIO2 deployment
    • request a downtime for AIO1 conversion
    • have an ISO with the QRadar version corresponding to the config backup file of AIO1 to have the possibility of a rollback.
    Implementation
    • Install extended license to AIO2
    • backup data from /store/Ariel on AIO1
    • get a config backup from AIO1, if you need to rollback
    • factory reset AIO1
    • reinstall AIO1 as EP1
    • patching to QRadar version of AIO2
    • Add managed host EP1 in AIO2 deployment
    • restore /store/ariel on EP1 from backup
    • enjoy

    I hope this helps. There are of course other possibilities with little downtime (for example a Temporary QRadar AIO1temp which continues to collect the logs during the conversion from AIO1 to EP1). I think the above described is the easiest way.

    Drop me a message, if you need more information.
    ------------------------------
    Kind regards
    Oliver
    ------------------------------