Example: stock market

IBM QRadar: Architecture and Deployment Guide

IBM and Deployment GuideIBM NoteBefore you use this information and the product that it supports, read the information in Notices onpage informationThis document applies to ibm qradar Security Intelligence Platform and subsequent releases unlesssuperseded by an updated version of this document. Copyright International Business Machines Corporation 2016, Government Users Restricted Rights Use, duplication or disclosure restricted by GSA ADP Schedule Contract withIBM to qradar 1. qradar Architecture 4 qradar events and 5 Chapter 2. qradar Deployment 12 Expanding deployments to add more remote collectors to a 14 Adding processing capacity to an All-in-One distributed Vulnerability Manager 19 qradar Risk Manager and qradar Vulnerability Manager.

analysis, reporting, and alerts or offense investigation. Users can search, and manage the security admin tasks for their network from the user interface on the QRadar Console. In an All-in-One system, all data is collected, processed, and stored on the All-in-One appliance.

Tags:

  Analysis, Architecture, Qradar, Ibm qradar

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of IBM QRadar: Architecture and Deployment Guide

1 IBM and Deployment GuideIBM NoteBefore you use this information and the product that it supports, read the information in Notices onpage informationThis document applies to ibm qradar Security Intelligence Platform and subsequent releases unlesssuperseded by an updated version of this document. Copyright International Business Machines Corporation 2016, Government Users Restricted Rights Use, duplication or disclosure restricted by GSA ADP Schedule Contract withIBM to qradar 1. qradar Architecture 4 qradar events and 5 Chapter 2. qradar Deployment 12 Expanding deployments to add more remote collectors to a 14 Adding processing capacity to an All-in-One distributed Vulnerability Manager 19 qradar Risk Manager and qradar Vulnerability Manager.

2 23 Forensics and full packet packets to qradar Packet 3. Data Nodes and data 4. App 5. HA Deployment 41 Chapter 6. Backup 43 qradar data 46 Terms and conditions for product 46 IBM Online Privacy 47 General Data Protection policy considerations .. 48 iiiiv Introduction to qradar deploymentsThe ibm qradar Deployment Guide helps you plan your qradar audienceThis information is intended for use by security administrators who are responsible for investigating andmanaging network security. To use this Guide you must have a knowledge of your corporate networkinfrastructure and networking documentationFor information about how to access more technical documentation, technical notes, and release notes,see Accessing IBM Security Documentation Technical Note ( ).

3 Contacting customer supportFor information about contacting customer support, see the Support and Download Technical Note( ).Statement of good security practicesIT system security involves protecting systems and information through prevention, detection andresponse to improper access from within and outside your enterprise. Improper access can result ininformation being altered, destroyed, misappropriated or misused or can result in damage to or misuse ofyour systems, including for use in attacks on others. No IT system or product should be consideredcompletely secure and no single product, service or security measure can be completely effective inpreventing improper use or access. IBM systems, products and services are designed to be part of alawful comprehensive security approach, which will necessarily involve additional operationalprocedures, and may require other systems, products or services to be most effective.

4 IBM DOES NOTWARRANT THAT ANY SYSTEMS, PRODUCTS OR SERVICES ARE IMMUNE FROM, OR WILL MAKE YOURENTERPRISE IMMUNE FROM, THE MALICIOUS OR ILLEGAL CONDUCT OF ANY Note:Use of this Program may implicate various laws or regulations, including those related to privacy, dataprotection, employment, and electronic communications and storage. ibm qradar may be used only forlawful purposes and in a lawful manner. Customer agrees to use this Program pursuant to, and assumesall responsibility for complying with, applicable laws, regulations and policies. Licensee represents that itwill obtain or has obtained any consents, permissions, or licenses required to enable its lawful use of IBMQR adar. Copyright IBM Corp. 2016, 2019vvi ibm qradar : Architecture and Deployment GuideChapter 1.

5 qradar Architecture overviewWhen you plan or create your ibm qradar Deployment , it's helpful to have a good awareness of QRadararchitecture to assess how qradar components might function in your network, and then to plan andcreate your qradar qradar collects, processes, aggregates, and stores network data in real time. qradar uses that datato manage network security by providing real-time information and monitoring, alerts and offenses, andresponses to network qradar SIEM (Security Information and Event Management) is a modular Architecture that providesreal-time visibility of your IT infrastructure, which you can use for threat detection and prioritization. Youcan scale qradar to meet your log and flow collection, and analysis needs. You can add integratedmodules to your qradar platform, such as qradar Risk Manager, qradar Vulnerability Manager, andQRadar Incident operation of the qradar security intelligence platform consists of three layers, and applies to anyQRadar Deployment structure, regardless of its size and complexity.

6 The following diagram shows thelayers that make up the qradar Architecture . Copyright IBM Corp. 2016, 20191 qradar ConsoleRouterSwitchUnix serversSyslogFirewall123 Data processingData storageData collectionData searchesReportsAlerts and offensesWindows serversGraphsNormalizationParsing321 User interfaceFlow dataScan dataEvent dataPacket capture for ForensicsConfiguration data for qradar Risk Manager Custom rulesQRadar Vulnerability ManagerNessusRapid7 Log sourceLog sourceOther dataLog sourceEvent CollectorEvent ProcessorFlow ProcessorFlow CollectorProxy serverLog sourceFigure 1. qradar architecture2 ibm qradar : Architecture and Deployment GuideThe qradar Architecture functions the same way regardless of the size or number of components in adeployment. The following three layers that are represented in the diagram represent the corefunctionality of any qradar collectionData collection is the first layer, where data such as events or flows is collected from your network.

7 TheAll-in-One appliance can be used to collect the data directly from your network or you can use collectorssuch as qradar Event Collectors or qradar QFlow Collectors to collect event or flow data. The data isparsed and normalized before it passed to the processing layer. When the raw data is parsed, it isnormalized to present it in a structured and usable core functionality of qradar SIEM is focused on event data collection, and flow data represents events that occur at a point in time in the user's environment such as user logins,email, VPN connections, firewall denys, proxy connections, and any other events that you might want tolog in your device data is network activity information or session information between two hosts on a network, whichQRadar translates in to flow records.

8 qradar translates or normalizes raw data in to IP addresses, ports,byte and packet counts, and other information into flow records, which effectively represents a sessionbetween two hosts. In addition to collecting flow information with a Flow Collector, full packet capture isavailable with the qradar Incident Forensics processingAfter data collection, the second layer or data processing layer is where event data and flow data are runthrough the Custom Rules Engine (CRE), which generates offenses and alerts, and then the data is writtento data, and flow data can be processed by an All-in-One appliance without the need for adding EventProcessors or Flow Processors. If the processing capacity of the All-in-One appliance is exceeded, thenyou might need to add Event Processors, Flow Processors or any other processing appliance to handle theadditional requirements.

9 You might also need more storage capacity, which can be handled by addingData features such as qradar Risk Manager (QRM), qradar Vulnerability Manager (QVM), or QRadarIncident Forensics collect different types of data and provide more Risk Manager collects network infrastructure configuration, and provides a map of your networktopology. You can use the data to manage risk by simulating various network scenarios through alteringconfigurations and implementing rules in your qradar Vulnerability Manager to scan your network and process the vulnerability data or manage thevulnerability data that is collected from other scanners such as Nessus, and Rapid7. The vulnerability datathat is collected is used to identify various security risks in your qradar Incident Forensics to perform in-depth forensic investigations, and replay full searchesIn the third or top layer, data that is collected and processed by qradar is available to users for searches, analysis , reporting, and alerts or offense investigation.

10 Users can search, and manage the security admintasks for their network from the user interface on the qradar an All-in-One system, all data is collected, processed, and stored on the All-in-One distributed environments, the qradar Console does not perform event and flow processing, or , the qradar Console is used primarily as the user interface where users can use it for searches,reports, alerts, and 1. qradar Architecture overview 3 qradar componentsUse ibm qradar components to scale a qradar Deployment , and to manage data collection andprocessing in distributed : Software versions for all ibm qradar appliances in a Deployment must be same version andfix pack level. Deployments that use different versions of software are not supported becauseenvironments that use mixed versions can cause rules not to fire, offenses not to be created or updated,and errors in search deployments can include the following components: qradar ConsoleThe qradar Console provides the qradar user interface, and real-time event and flow views, reports,offenses, asset information, and administrative distributed qradar deployments, use the qradar Console to manage hosts that include Event CollectorThe Event Collector collects events from local and remote log sources, and normalizes raw log sourceevents to format them for use by qradar .


Related search queries