Reader small image

You're reading from  Building a Next-Gen SOC with IBM QRadar

Product typeBook
Published inJun 2023
PublisherPackt
ISBN-139781801076029
Edition1st Edition
Right arrow
Author (1)
Ashish M Kothekar
Ashish M Kothekar
author image
Ashish M Kothekar

Ashish has a total experience of more than 15 years working for IBM on various different platforms. He is currently working as tech evangelist for IBM Security products. He has been instrumental in developing more than 10 IBM certification exams including IBM products like QRadar, Cloud Pak for Security, IBM SiteProtector, IBM XGS, etc. He has worked with multiple customers on deploying and then upgrading IBM security products. He has contributed regularly by writing blogs and giving talks on security products. He has published many redpapers on the integration of security products with IBM Storage solutions like IBM Spectrum scale. These redpapers are now full-fledged solutions that are being sold. He has also cleared two Mandarin language exams and is HSK2 qualified.
Read more about Ashish M Kothekar

Right arrow

Re-Designing User Experience

IBM QRadar has been a pioneer when it comes to deep packet inspection and event correlation, providing out-of-the-box rules and hundreds of extensions and apps. It has been the quadrant leader in the Gartner report for the last 12 years. This is no mean feat. But one aspect where IBM QRadar needed improvement was the intuitiveness of the user interface. For the analysts and admins, using QRadar involved a relatively steep learning curve. The dashboards and results had to be analyzed and filtered to make sense. The offense investigations took a lot of effort in terms of the skill and time required from analysts. With all this feedback on the user experience, IBM QRadar came up with the QRadar Analyst Workflow app. While working on QRadar Analyst Workflow, a new app specifically for the dashboards called QRadar Pulse was also developed and published. The QRadar Experience Center app was designed for the end user to simulate attacks and observe what a real...

QRadar Analyst Workflow

As we have seen in previous chapters, QRadar is a great security product that handles complex rules, collects different types of event and flow data, provides exceptional results in terms of performance, and helps with regulatory compliance. To enhance the user experience, QRadar Analyst Workflow provides an alternative user interface consisting of the following:

  • Search view
  • Pulse dashboards
  • Offenses view

We will discuss these components in detail in the following sub-sections.

Important note

IBM QRadar Pulse is an app like any other. It is also part of QRadar Analyst Workflow. This was done as QRadar Analyst Workflow offers a much better user experience than the legacy user interface. Pulse is part of the new user experience.

Exploring the Search view

Analysts need to perform tasks such as event searches, and the Log Activity tab in QRadar Analyst Workflow provides multiple ways to run such searches. One of these is via Ariel...

QRadar Pulse dashboard app

QRadar provides a variety of dashboards in its user interface. However, depending on your requirements, these dashboards may need a lot of customization. The problem is that the default dashboards are not very intuitive and often cannot be used as is, while customizing them takes time and research. IBM understood this challenge and created the Pulse app to provide customers with out-of-the-box dashboards for different purposes:

Figure 10.5 – Pulse dashboard app

Figure 10.5 – Pulse dashboard app

Important note

QRadar Analyst Workflow has hyperlinks or is connected to other applications including Pulse, User Behavior Analytics, Use Case Manager, and QRadar Assistant. This is done to provide a single pane of glass for all the UI dashboards needed by SOC analysts in their day-to-day work.

In the preceding figure, we can see the Summary view of the Pulse application. On this page, we can see the following components:

  • Time_Span: This determines...

QRadar Experience Center

When considering user experience in QRadar, we have to mention the QRadar Experience Center app. This application is developed for customers who are very new to QRadar to help them understand how QRadar works and is best suited for test environments. It provides automated simulations to help us understand how attacks are designed, what exactly happens when attacks occur, and how we can respond.

There are multiple other items imported when you install the QRadar Experience Center app. The current version of the app, there are about 50 custom event properties (CEPs), 36 custom rules, 16 log sources, and 11 saved searches. All this data is then used by the app to simulate attacks.

After installing QRadar Experience Center, logging in to IBM QRadar, and then going to the Log Activity tab, you will see the following screen:

Figure 10.8 – Launch QRadar Experience Center

Figure 10.8 – Launch QRadar Experience Center

In the preceding figure, we can see the option to launch...

Creating your own app

In this chapter, we discussed the different apps available to enhance the QRadar user experience. Even with the level of sophistication offered, there could still be certain ways that you would like to consume QRadar data not offered by these apps. Also, there could be multiple applications for which you require support not yet provided by IBM.

IBM Security App Exchange is the portal on which IBM (among other vendors) publishes applications and extensions that can be downloaded and used by anyone. You need to log in using your IBM ID to access these resources on the exchange portal.

Imagine a scenario where a company named ABC has a software solution for its customer relationship management (CRM) needs. The software solution also generates security logs. Company ABC would like to integrate these security logs with QRadar. In such a scenario, company ABC can create a document explaining how to fetch logs from the software solution and send them to QRadar...

Summary

We have seen how QRadar is a powerful tool that works with tons of data and different configurations. For the end user, QRadar apps make it easier to visualize and manipulate this data. In this chapter, we have learned how to enhance the QRadar user experience. Creating dashboards, customizing views, and sharing saved searches are a few of the ways to efficiently use QRadar. QRadar Analyst Workflow offers a next-gen user interface to visualize our offense and search data in a completely different way. This new GUI is pretty intuitive too. Similarly, QRadar Pulse provides many pre-defined dashboards. These dashboards can be customized further.

In the next chapter, we will study WinCollect, which is a Windows agent for QRadar.

lock icon
The rest of the chapter is locked
You have been reading a chapter from
Building a Next-Gen SOC with IBM QRadar
Published in: Jun 2023Publisher: PacktISBN-13: 9781801076029
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
undefined
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime

Author (1)

author image
Ashish M Kothekar

Ashish has a total experience of more than 15 years working for IBM on various different platforms. He is currently working as tech evangelist for IBM Security products. He has been instrumental in developing more than 10 IBM certification exams including IBM products like QRadar, Cloud Pak for Security, IBM SiteProtector, IBM XGS, etc. He has worked with multiple customers on deploying and then upgrading IBM security products. He has contributed regularly by writing blogs and giving talks on security products. He has published many redpapers on the integration of security products with IBM Storage solutions like IBM Spectrum scale. These redpapers are now full-fledged solutions that are being sold. He has also cleared two Mandarin language exams and is HSK2 qualified.
Read more about Ashish M Kothekar