IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only

#BeyondTheDSMGuide Quick Hit: QRadar’s AWS Integrations

By Wendy Willner posted Sun April 18, 2021 05:24 PM

  

The QRadar team has been releasing some awesome new features and functions related to hybrid cloud detection. See below for a quick summary of our AWS Integrations.I’ll be following up this article with several other deeper dives into these topics!

Parsers (DSMs):

  1. AWS CloudTrail: Here
  2. AWS Network Firewall: Here
  3. AWS Security Hub: Here
  4. AWS VPC Flow Logs: Here
  5. AWS Guard Duty: Here
  6. AWS Web Application Firewall: Here
  7. AWS Application Load Balancer: Here
  8. AWS Elastic Kubernetes Service: Here

AWS Protocols (Mechanism for pulling data into QRadar):

  1. AWS S3 Protocol: Here
    1. This protocol allows users to directly pull data from S3 buckets into QRadar
  2. Amazon Web Services Protocol: Here
    1. This protocol allows users to pull AWS data directly from CloudWatch Logs, Simple Queue Service (SQS) and Kinesis Data Streams into QRadar

See below for a graphical summary:

These integrations are available for users leveraging QRadar wherever it is hosted: QRoC (QRadar SaaS), QRadar on-prem, QRadar deployed in AWS, Azure or GCP.

 

Since, we’re on the topic of QRadar and AWS, I’d like to share that IBM Security has achieved AWS Security Technology Partner Status! A great article by my friend and teammate, George Mina can be found (here) with all of the details.

If you are leveraging any of these integrations, I’d also recommend checking out our Cloud Visibility App on the App Exchange (here).  This app includes:

  • Simplified log source management
  • Identity and access management for accounts, users, and IAM roles
  • Auto-population of QRadar Network Hierarchy
  • Amazon VPC flow log visualization
  • Integration with AWS Security Hub and Amazon Detective

 

Is your team taking advantage of these integrations? Let me know!!

Thanks,

Wendy

 
















0 comments
27 views

Permalink