Be aware, if you do anything other than backup/restore then the identifiers in the Ariel data migrated will not match the identifiers in the QRadar configuration. This means that, for example, an event linked to a log source with identifier X will be at best shown as an 'unknown' log source, and at worst, linked to the wrong log source entirely.
This is true for many configuration items (rules, etc...)
What this means is that although the data is there - and it is "migrated", it will look very strange and searching it may be very difficult indeed (depending on what you will be trying to search on).
Also, using CMT or other similar tools to migrate rules etc... can be very unpredictable as the tool may need to reconcile rules that have been modified differently in the source and target systems - how does it know which modification is 'correct'?
Finally, if you do use a tool like CMT - ensure you migrate everything you need to migrate at once - that way CMT has a fighting chance of modifying references that change between systems. If you try to, say, modify the log sources separately to the rules - then any log source references in the rules will not be migrated correctly.
Super-finally - be very careful with Custom Log Source types - they can really trip you up.
Bottom line - this is really quite tricky and it is very easy the think you've done it - but actually the system you create is not migrated properly at all.
------------------------------
Paul Ford-Hutchinson
------------------------------
Original Message:
Sent: Thu July 03, 2025 09:59 AM
From: Vydenis Kucinskas
Subject: QRadar Multi-tenancy for MSSP
Hi,
Does anyone have experience with migrating QRadar from a single-tenant setup to a multi-tenant environment?
Question:
Is it possible to migrate data in this scenario, where client A was previously using an QRadar all-in-one console?
We are planning to replace the existing all-in-one console with a dedicated Event Flow Processor and connect it to a centralized console.
The main question is:
How can we migrate log source keys, network hierarchy, historical events, and other related configurations?
When migrating from one all-in-one console to another, the process is relatively straightforward, but what about this case?
BR
------------------------------
Vydenis Kucinskas
------------------------------