IBM Security QRadar

 View Only
  • 1.  DO I NEED DOMAIN ADMIN?

    Posted Wed November 23, 2022 07:47 AM
    Hello,

    I want to ask you something. Is it necessary to have a domain admin user for IBM Qradar? So, is there such a need?

    Thank you,
    Kind Regards.



    ------------------------------
    Fatih R
    ------------------------------


  • 2.  RE: DO I NEED DOMAIN ADMIN?

    Posted Thu November 24, 2022 04:28 AM
    I think you should define the question a bit better... QRadar by default uses local authentication (locally defined users and roles). If you are referring to using Active Directory as LDAP for authentication, when you are using authenticated bind you need a user that can read the LDAP directory. Instructions how to configure LDAP authentication can be found in IBM's documentation. You can e.g. opt to use group based authentication and allow/deny the groups of users per defined roles and security profiles (I recall there were some examples for that on you tube etc.).

    ------------------------------
    Dusan VIDOVIC
    ------------------------------



  • 3.  RE: DO I NEED DOMAIN ADMIN?

    Posted Thu November 24, 2022 03:55 PM
    You do not need Domain Admin rights and should never monitor anything
    within an enterprise using such a level of access. Windows permission
    architecture should have specific service accounts with appropriate
    permissions where auth is necessary such as LDAP read (which any
    auth'ed user in a windows domain can actually do) or any sort of
    active retrieval requiring authentication.

    DA is not needed to interact with QRadar using LDAP auth for QRadar
    either access should be handled by a AD ad group.




  • 4.  RE: DO I NEED DOMAIN ADMIN?

    Posted Thu December 15, 2022 03:17 PM
    I understand, but our SIEM admins always want domain admin, they log using this, is there any logic to this?

    ------------------------------
    Fatih R
    ------------------------------



  • 5.  RE: DO I NEED DOMAIN ADMIN?

    Posted Thu December 15, 2022 03:23 PM
    User logins for QRadar linked to LDAP do not require domain admin
    level permissions, Using service accounts with domain admin level of
    privileges to retrieve logs is a substantial increase in risk posture.

    For retrieving windows logs, wincollect and/or WEF are more manageable
    and scalable solutions for retrivening windows logs without requiring
    individual log sources to use authentication.




  • 6.  RE: DO I NEED DOMAIN ADMIN?

    Posted Fri December 16, 2022 11:56 AM
    I understand, let me ask the question differently. Siem administrators say we need a domain admin and I say why, they say we cannot collect logs without a domain admin. I am trying to understand this, is there such a thing? For example, if there is no domain when adding the log source, some logs will not come, is there such a thing? So is this information correct?

    ------------------------------
    Fatih R
    ------------------------------



  • 7.  RE: DO I NEED DOMAIN ADMIN?

    Posted Sat December 17, 2022 02:49 AM

    To collect logs from Windows systems (if that is the question), it ishoild not be necessary to use domain admin accounts - the user account used to collect logs from the system should be member of the Event Log Readers group (as is stated in the documentation - and tested). I recall having some problems with Windows 2003 (but I guess this is not the case here - or you have a whole different issue using an obsolete unsupoorted OS). 



    ------------------------------
    Dusan VIDOVIC
    ------------------------------