IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  QRadar network flows and interfaces

    Posted Fri April 23, 2021 10:10 AM
    Hello.
    We want to handle network flows flow Cisco devices with QRadar. QRadar will be installed as a VMWARE ESXi virtual machine. We plan to separate management interface that is used to manage QRadar via its GUI and the interface that network flows will be sent to. As far as I understand QRadar network interface that is responsible for handling network flows should be set to promiscuous mode. Am I right? Or QRadar is able to handle flows even when this interface isn't in promiscuous mode?

    ------------------------------
    Igor Volkov
    ------------------------------


  • 2.  RE: QRadar network flows and interfaces

    Posted Fri April 23, 2021 12:15 PM
    Hello Igor,

    there are several options to handle flow information with QRadar. I'll try to give you a simple statement to your questions:
    If you want to monitor a vswitch in an ESX Environment with your QRadar VM, which is connected to this vswitch with one interface, this vswitch needs to be set in promiscuous mode to handle the flows of this vswitch.

    In case of handle flows from cisco devices, one way could be just to forward flows from the cisco device to QRadar. If you use an AiO (All-In-One) QRadar Deployment, it's the IP of AiO. If you use a managed host deployment, for example console, FP (Flow Processor), EP (Event Processor), etc. you should use the IP in this case of the FP host for example...

    Hope this helps.

    Regards,
    Ralph

    ------------------------------
    Ralph Belfiore
    SIEM Expert
    pro4bizz GmbH
    Karlsruhe
    +49 721 90981727
    ------------------------------



  • 3.  RE: QRadar network flows and interfaces

    Posted Wed May 05, 2021 05:55 AM
    Just a note (... maybe this can be a viable option): we've used in our lab vSphere with vCenter (6.7/7.x) and a distributed virtual switch (v 6.6);  d.v.switch allows setting NetFlow export to an IP and port you choose, and QRadar recognizes this as it would any other standard NetFlow source.

    ------------------------------
    Dusan VIDOVIC
    ------------------------------