QRadar
SIEMIBM's SIEM for correlating events and detecting offences.
Who uses it?
SOC analysts and security engineers in organisations that run QRadar.
Best for
Grouping related events into offences for triage
Similar tools
Splunk, Microsoft Sentinel
What is it?
QRadar is a SIEM from IBM that collects events and network flow data and groups related activity into offences.
What problem does it solve?
Analysts need related events grouped so they can prioritise what to investigate instead of reading each log line.
How does it work?
Log sources and network flows are collected and parsed. Rules correlate events and raise offences. Analysts investigate offences and the events behind them.
Simple example
A series of related suspicious events on one host are grouped into a single offence for review.
When would a SOC analyst use it?
When triaging a queue of offences and deciding which need escalation.
How does it work?
- 1Log sources and network flows are collected and parsed.
- 2Rules correlate events and raise offences.
- 3Analysts investigate offences and the events behind them.
Simple example
A series of related suspicious events on one host are grouped into a single offence for review.
When would a SOC analyst use it?
When triaging a queue of offences and deciding which need escalation.
Who uses it?
SOC analysts and security engineers in organisations that run QRadar.
Pros
- Groups related events for analysts
- Includes network flow analysis
- Established in large organisations
Cons
- Can be complex to administer
- Rule tuning takes ongoing effort
- Licensing can be complex