Today marks the release of the IBM QRadar Data Synchronization App. This post will give a brief overview of its key capabilities and the problems it solves. There have been many questions concerning its functionality and use case coverage; many of these common questions are answered at the end.
Disaster Recovery (DR) is a key aspect to the resiliency of a QRadar deployment. There is a wide variety of solutions currently deployed in the field for DR, including: redundant console only configurations, event and flow forwarding based solutions, and even full event distribution to two deployments (often termed "dual home"). These solutions vary greatly in terms of complexity, cost, and effectiveness. However, for the most part, customers rely on significant customization, usually offered by IBM professional services, in the setup and configuration on their DR solution.