Reader small image

You're reading from  Building a Next-Gen SOC with IBM QRadar

Product typeBook
Published inJun 2023
PublisherPackt
ISBN-139781801076029
Edition1st Edition
Right arrow
Author (1)
Ashish M Kothekar
Ashish M Kothekar
author image
Ashish M Kothekar

Ashish has a total experience of more than 15 years working for IBM on various different platforms. He is currently working as tech evangelist for IBM Security products. He has been instrumental in developing more than 10 IBM certification exams including IBM products like QRadar, Cloud Pak for Security, IBM SiteProtector, IBM XGS, etc. He has worked with multiple customers on deploying and then upgrading IBM security products. He has contributed regularly by writing blogs and giving talks on security products. He has published many redpapers on the integration of security products with IBM Storage solutions like IBM Spectrum scale. These redpapers are now full-fledged solutions that are being sold. He has also cleared two Mandarin language exams and is HSK2 qualified.
Read more about Ashish M Kothekar

Right arrow

How do searches work?

Though we have briefly discussed the idea of searching, let us dig deep into it and understand the mechanism of QRadar search.

Figure 6.1 – Components involved in a QRadar search

Figure 6.1 – Components involved in a QRadar search

In the preceding figure, we have tried to cover all the QRadar components that are involved in a QRadar search. We can see a security analyst on the left-hand side trying to run a search on the QRadar Console Graphical User Interface (GUI). We can also see three Event Processors and one Flow Processor where data is stored. Then there are Data Node 1 and Data Node 2, which are attached to Event Processor 2. There are two Event Collectors, which are collecting logs, and those logs are stored on Event Processor 1. Similarly, flows are collected by QRadar Network Insights (QNI) and another Flow Collector (QFlow service) and are sent to the Flow Processor.

In the figure, we can see legends that are defined. The blue colored line depicts the search query...

lock icon
The rest of the page is locked
Previous PageNext Page
You have been reading a chapter from
Building a Next-Gen SOC with IBM QRadar
Published in: Jun 2023Publisher: PacktISBN-13: 9781801076029

Author (1)

author image
Ashish M Kothekar

Ashish has a total experience of more than 15 years working for IBM on various different platforms. He is currently working as tech evangelist for IBM Security products. He has been instrumental in developing more than 10 IBM certification exams including IBM products like QRadar, Cloud Pak for Security, IBM SiteProtector, IBM XGS, etc. He has worked with multiple customers on deploying and then upgrading IBM security products. He has contributed regularly by writing blogs and giving talks on security products. He has published many redpapers on the integration of security products with IBM Storage solutions like IBM Spectrum scale. These redpapers are now full-fledged solutions that are being sold. He has also cleared two Mandarin language exams and is HSK2 qualified.
Read more about Ashish M Kothekar