IBM Security QRadar

 View Only
  • 1.  QRadar Data Gateway vs. Event Collector vs. Disconnected Event Collector

    Posted Thu April 04, 2019 05:42 AM
    Hi,

    I'm considering to collect events to QRadar SIEM environment from remote and untrusted sites, i.e. untrusted and unreliable (virtual) hardware and unreliable network connectivity.  I'm trying to find the best piece of software to use as an "event proxy" to QRadar while keeping good level of operations and security for the whole SIEM environment.

    I see four options , none of them being perfect:
    1. IBM QRadar Data Gateway
      • Pros: meets (most) requirements for security and operations
      • Cons: only available for QRoC (QRadar-on-Cloud)
    2. IBM QRadar Event Collector
      • Pros: native event collection and parsing
      • Cons security: configuration for all log sources is pushed to remote untrusted site, not just site specific log sources
      • Cons operations: problems with hardware or network on remote site causes problems to whole QRadar deployment (e.g. during Deploy operations)
    3. IBM QRadar Disconnected Event Collector
      • Pros: local issues do not impact whole QRadar deployment
      • Cons: Cannot be centrally managed, only supports syslog for collection (not ODBC, RPC, HTTPS API, etc.)
    4. non-IBM custom-made event proxy (e.g. LogStash, syslog-ng, etc.)
      • Pros: flexible
      • Cons operations: software not supported by IBM
      • Cons operations: questionable DSM support for the forwarded events (e.g. forwarded csv pulled from a DB via ODBC)
    I would appreciate any opinions and experience on this.  Thank you!

    ------------------------------
    Martin
    ------------------------------


  • 2.  RE: QRadar Data Gateway vs. Event Collector vs. Disconnected Event Collector

    Posted Wed May 15, 2019 04:09 AM
    Anyone can comment?  Thanks!

    ------------------------------
    Martin
    ------------------------------



  • 3.  RE: QRadar Data Gateway vs. Event Collector vs. Disconnected Event Collector

    Posted Wed May 15, 2019 07:44 AM
    Hello 
    My be you can use some open source syslog solution and forwards the events to your qradar, be carfull about the date of events !

    ------------------------------
    [Larbi] [Belmiloud]
    [Cyber Security]
    [Intervalle Technologies]
    [Algers] [Algeria]
    [+213551193200]
    ------------------------------



  • 4.  RE: QRadar Data Gateway vs. Event Collector vs. Disconnected Event Collector

    Posted Thu May 16, 2019 06:58 AM
    Thank you, Larbi.

    Using an opensource tool is the option 4 in the original post.  Indeed, log source time and date would be one of the things to look after during parsing.

    Martin

    ------------------------------
    Martin
    ------------------------------