Reader small image

You're reading from  Building a Next-Gen SOC with IBM QRadar

Product typeBook
Published inJun 2023
PublisherPackt
ISBN-139781801076029
Edition1st Edition
Right arrow
Author (1)
Ashish M Kothekar
Ashish M Kothekar
author image
Ashish M Kothekar

Ashish has a total experience of more than 15 years working for IBM on various different platforms. He is currently working as tech evangelist for IBM Security products. He has been instrumental in developing more than 10 IBM certification exams including IBM products like QRadar, Cloud Pak for Security, IBM SiteProtector, IBM XGS, etc. He has worked with multiple customers on deploying and then upgrading IBM security products. He has contributed regularly by writing blogs and giving talks on security products. He has published many redpapers on the integration of security products with IBM Storage solutions like IBM Spectrum scale. These redpapers are now full-fledged solutions that are being sold. He has also cleared two Mandarin language exams and is HSK2 qualified.
Read more about Ashish M Kothekar

Right arrow

UBA application tuning

The UBA app, along with the ML app,needs a lot of tuning as per your environment. We have seen that the UBA application has so many configuration parameters. We have already mentioned that if you plan to use UBA, you should install App Host as UBA is a computationally heavy app. The number of resources made available to the UBA and ML apps may limit the number of users that can be monitored. If the number of users becomes high, UBA will require more computational resources, which will in turn hamper performance as the UBA app’s graphical interface can become slow or unresponsive.

Some basic tuning tips for the UBA and ML apps are as follows:

  • Import users using a directory server/LDAP/CSV file

We have seen that there are many ways in which users are added. In Figure 8.2, we saw a few users were discovered using event data such as events and flows. For most of these users, the event data has users such as admin and root that cannot be correlated...

lock icon
The rest of the page is locked
Previous PageNext Page
You have been reading a chapter from
Building a Next-Gen SOC with IBM QRadar
Published in: Jun 2023Publisher: PacktISBN-13: 9781801076029

Author (1)

author image
Ashish M Kothekar

Ashish has a total experience of more than 15 years working for IBM on various different platforms. He is currently working as tech evangelist for IBM Security products. He has been instrumental in developing more than 10 IBM certification exams including IBM products like QRadar, Cloud Pak for Security, IBM SiteProtector, IBM XGS, etc. He has worked with multiple customers on deploying and then upgrading IBM security products. He has contributed regularly by writing blogs and giving talks on security products. He has published many redpapers on the integration of security products with IBM Storage solutions like IBM Spectrum scale. These redpapers are now full-fledged solutions that are being sold. He has also cleared two Mandarin language exams and is HSK2 qualified.
Read more about Ashish M Kothekar