IBM Security QRadar

 View Only

IBM Security QRadar SIEM and Alibaba ActionTrail integration

By Olga Hout posted Mon December 18, 2023 08:44 PM

  

Our team has been fully engaged this past quarter and is finishing up strong! 

With great pleasure, we'd like to announce a highly anticipated integration between IBM Security QRadar SIEM and Alibaba ActionTrail.

Alibaba Actiontrail Log Source Summary

What is ActionTrail?

ActionTrail is a service that monitors and records the operations of your Alibaba Cloud account. These operations include your access to and use of cloud services with the help of the Alibaba Cloud Management Console, APIs, and SDKs. ActionTrail records these operations as events. ActionTrail can log to LogStores and Object Storage (OSS) buckets, which is highly stable and reliable. Log Service and OSS allow you to encrypt the audit data and manage access permissions on the audit data. This ensures high security of the audit data.

What is Alibaba Cloud Log Service?

It is a complete real-time data logging service that supports collection, consumption, shipping, search, and analysis of logs, and improves the capacity of processing and analyzing large amounts of logs. It can send logs to SIEM over Syslog or HTTPs. Additionally, APIs and SDKs support multiple features and programming languages, to easily manage and serve more than one million devices.

What is the use case?

Alibaba Cloud ActionTrail monitors and records your access and use of cloud products and services as events and ingests these events into QRadar SIEM for security analysis. 

When in the Log Activity tab in QRadar SIEM, you'll be able to get a list of event names and their count, detailing the time, level category, source and destination IP, and other event indicators. 

Log Activity Actiontrail
Resources
For more details on specifications and a sample event for Alibaba CloudTrail DSM, navigate to IBM Security DSM Guide. To download the functionality, head over to our FixCentral portal
Please note: Administrators must install the Alibaba Cloud Object Storage protocol to collect events from remote object storage buckets, create a user permission in their Alibaba Cloud account for the log source, and a service credentials for the protocol.
I'd like to thank our engineering team, along with the integrations team managers Mehul Chauhan and Kajal Sangani for their partnership and hard work.
Please, let us know if you plan on using this new functionality and share your feedback with the IBM Security team.
0 comments
10 views

Permalink