I have been reading QRadar component documentation and I've the following hypothetical question: let's imagine a distributed deployment with appliances for Event Collector, Event Processor, Flow Collector, Flow Processor and a console (not an All-in-one). As far as I know, events are processed by the CRE that resides in QRadar Event Processor. Flows are processed in QRadar Flow Processor. But, what happens with common rules (those that use flows and events)? who is responsible of processing this type of rules that search for event and flow data?
Thanks in advanced
------------------------------
A CG
------------------------------