Hi Usama, Greetings!
QRadar uses an SSH-based tunnel infrastructure for inter-host communications (Console ↔ Managed Hosts, EC ↔ EP, EP ↔ Data Nodes, etc). Many internal services communicate through QRadar-managed SSH tunnels regardless of whether payload encryption/compression options are enabled.
The observed SSH traffic between the Event Collector and Event Processor is expected behavior. In QRadar, disabling the Managed Host encryption/compression options does not remove the underlying SSH-based communication framework used between managed hosts. These settings affect how data is handled within the communication channel rather than forcing direct unencrypted TCP communication. At present, QRadar does not provide a supported method to disable SSH transport between managed hosts or force plain TCP communications for ECS traffic.
Ref Link: https://www.ibm.com/docs/en/qradar-on-cloud?topic=hosts-encryption
Regards,