IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  QROC Data Gateway

    Posted Tue March 17, 2020 08:04 AM
    Has anyone deployed without Data Gateway which i mean send the logs from the devices directly to event processor on cloud cutting the data gateway in between ? Or can we have all in one deployment for QRADAR in cloud please?

    ------------------------------
    Karthick Krishnamoorthy
    ------------------------------


  • 2.  RE: QROC Data Gateway

    Posted Tue March 17, 2020 08:18 AM
    You can have an AIO in cloud, deployment in AWS for instance. QROC
    without a gateway would at the least require VPN established for on
    prem and you would have no event caching collection locally which
    would be a collection risk. I do not think that is supported.

    For 100% cloud, running to a bucket then leveraging API log sources
    direct from QROC is an alternative, where all the logging effort stays
    cloud local and you just hit API to grab events/flow logs.




  • 3.  RE: QROC Data Gateway

    Posted Tue March 17, 2020 09:44 AM
    Thank you very much for your response. Our log sources are all on-prem, our concern here is the hardware cost for the Data Gateway and we are working the way around if available to avoid the hardware cost for data Gateway. I presume the API will be applicable for the cloud based log sources if am not wrong ?

    ------------------------------
    Karthick Krishnamoorthy
    ------------------------------



  • 4.  RE: QROC Data Gateway

    Posted Wed March 18, 2020 03:49 AM
    In general, when deploying managed hosts (e.g. AiO + Event Collector...) there should be a minimum of 100Mbps bandwidth between them - due to a need to replicate configuration and status data. However, I would advise to have Processors quite "close" to the console, as searches and global correlation could be impacted otherwise. I would suggest you evaluate if Disconnected Log Collector could be of use in your case (it can be deployed on a computer or virtual machine with RHEL7.x or CentOS 7.x and reasonable resources you provide).

    ------------------------------
    Dusan VIDOVIC
    ------------------------------