IBM Security QRadar

 View Only
  • 1.  Qradar on Cloud

    Posted Fri June 26, 2020 06:50 AM
    Hi All,

    I would like to understand can we use MSRPC protocol to collect the Windows server event logs in Qradar on Cloud please ? Because in an article it is mentioned that we wont be able to use managed version of Wincollect agent hence i am not sure does Qradar on Cloud support RPC protocol ? 

    Regards,
    Karthick

    ------------------------------
    Karthick Krishnamoorthy
    ------------------------------


  • 2.  RE: Qradar on Cloud

    Posted Mon June 29, 2020 10:30 AM
    Hi Karthick,

    Yes the MSRPC protocol should work fine in a QRadar on Cloud environement. If you configure it to run on a Data Gateway it can collect the Windows events from the local on-prem Windows systems.

    Cheers
    Colin

    ------------------------------
    COLIN HAY
    IBM Security
    ------------------------------