IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  CP4S for UAX+SOAR on on-prem environment

    Posted Thu March 07, 2024 04:18 AM

    Hello All,

    Is it possible to install CP4S UAX+SOAR in on-prem data center. We have our qradar environment installed on prem and we want to explore the new CP4S UAX+SOAR  capability by integrating this with on-prem qradar.

    If this is possible please guide me with the right documentation.

    Thanks in advance. 



    ------------------------------
    Punith Rajanna
    ------------------------------


  • 2.  RE: CP4S for UAX+SOAR on on-prem environment

    Posted Thu March 07, 2024 07:18 AM

    Punith,

    yes you can do this if you provide all the infrastructure needed for CP4S SOAR (new Qradar suite) in your data center. However not a good idea for exploring the capabilities of CP4S. its much easier to integrate your on prem install with a small clod based environment. Less costs, less time and material! I had the chance for beta testing last summer. Here some more input on this. 

    There are new capabilities for combining traditional and cloud based QRadar. Wendy Batten has posted a nice demo August 2023 pls see

    https://community.ibm.com/community/user/security/discussion/ibm-security-qradar-soar-demo?ReturnUrl=%2fcommunity%2fuser%2fsecurity%2fcommunities%2fcommunity-home%2fdigestviewer%3fcommunitykey%3dd2f71e8c-108e-4652-b59c-29d61af7163e

    If you want to read the latest documentation on log Insights and offense forwarder look at https://www.ibm.com/docs/en/security-qradar/log-insights/saas?topic=overview-setting-up-qradar-offenses-forwarder

    Any questions are welcome. Here are two screenshots to give you an idea on alert cases automatically created from on prem offenses in CP4S

    picture1
    image2
    picture2


    ------------------------------
    [Karl] [Jaeger] [#ibmchampion]
    [QRadar Specialist]
    [cnag]
    [Siegen] [Germany]
    ------------------------------