Readme file
Introduction
IBM® QRadar® Suite can connect disparate data sources—to uncover hidden threats and make better risk-based decisions — while leaving the data where it resides. By using open standards and IBM innovations, IBM® QRadar® Suite can securely access IBM and third-party tools to search for threat indicators across any cloud or on-premises location. Connect your workflows with a unified interface so you can respond faster to security incidents. Use IBM® QRadar® Suite to orchestrate and automate your security response so that you can better prioritize your team's time.
What's inside this Cloud Pak
Cloud Pak® for Security includes the following applications.
- IBM® Threat Intelligence Insights is an application that delivers unique, actionable, and timely threat intelligence. The application provides most of the functions of IBM® X-Force® Exchange.
- IBM® Security Data Explorer is a platform application that enables customers to do federated search and investigation across their hybrid, multi-cloud environment in a single interface and workflow.
- IBM® Case Management for IBM® QRadar® Suite provides organizations with the ability to track, manage, and resolve cybersecurity incidents.
- IBM® Orchestration & Automation application is integrated on QRadar Suite to provide most of the IBM Resilient Security Orchestration, Automation, and Response Platform feature set.
- IBM® QRadar® Security Intelligence Platform is offered as an on-premises solution and delivers intelligent security analytics, enabling visibility, detection, and investigation for a wide range of known and unknown threats.
- IBM® QRadar® Proxy 1.0 provides communication between IBM® QRadar® Suite and IBM QRadar or QRadar on Cloud. This communication uses APIs to pull powerful QRadar data into the QRadar SIEM dashboards.
- IBM® QRadar® User Behavior Analytics (UBA) is a tool for detecting insider threats in your organization. UBA, used in conjunction with the existing data in your QRadar system, can help you generate new insights around users and user risk.
- IBM® Threat Investigator is an application that automatically analyzes and investigates cases to help determine the criticality of exposure, how many systems are at risk, and the level of remediation effort that is required.
- IBM® Detection and Response Center provides an overview of your organization’s security posture through the security use cases available from IBM QRadar and the Sigma community tools. IBM® Threat Investigator uses these security use cases in its investigations.
For more information, see IBM Documentation.
Prerequisites
Red Hat OpenShift Container Platform
Please refer to the Planning
section in the IBM Documentation.
Resource capacity requirements
Node type | Number of nodes | CPU | RAM | Storage |
---|---|---|---|---|
Worker | 3 | 16 cores | 64 GB | 120 GB |
Note: The system disk requirements do not include the persistent storage requirements. The persistent storage requirement for IBM® QRadar® Suite is 3.5 TB. For more information, see Persistent storage.
Purchasing a license
Before you can install the Cloud Pak, you must purchase a license. Purchase a license, also known as an entitlement, through IBM Passport Advantage.
Installing
For installation instructions, see https://cloud.ibm.com/docs/cloud-pak-security. The installation takes approximately 1.5 hours to complete.
Configuration
The following table lists the configurable parameters for Cloud Pak® for Security and their default values.
Required Values | Description | Default |
---|---|---|
adminUser | The Admin user who will be given administrative privileges in the default account. |
Optional Values | Description | Default |
---|---|---|
domain | The Fully Qualified Domain Name (FQDN) created for QRadar Suite. When the domain is not specified, it will be generated as cp4s. . |
|
domainCertificate | TLS certificate associated to the IBM Pak® QRadar Pak® Suite for Security application domain. If the domain is not specified, OpenShift cluster certificates will be used. For more information, see TLS certificate. |
|
domainCertificateKey | TLS key associated to the IBM Pak® QRadar Pak® Suite for Security application domain. If the domain is not specified, OpenShift cluster certificates will be used. For more information, see TLS certificate. |
|
customCA | Custom TLS certificate associated to the IBM Pak® QRadar Pak® Suite for Security application domain. If the domain is not specified, OpenShift cluster certificates will be used. For more information, see TLS certificate. |
|
storageClass | The provisioned block or file storage class to be used for creating all the PVCs required by IBM Pak® QRadar Pak® Suite for Security. When it is not specified, the default storage class in the cluster will be used. | |
backupStorageClass | Storage class used for creating the backup PVC. If this value is not set, IBM Pak® QRadar Pak® Suite for Security will use the same value set in storageClass parameter. |
|
backupStorageSize | Override the default backup storage PVC size. | 500Gi |
imagePullPolicy | Image pull policy for the containers. | IfNotPresent |
deployDRC | Deploy Detection and Response Center application. Optional when deploying QRadar Suite. See more details in (https://www.ibm.com/docs/en/SSTDPP_1.10/docs/drc/c_DRC_intro.html). | true |
deployThreatInvestigator | Deploy Threat Investigator application. Optional when deploying Cloud Pak for Security. See more details in (https://www.ibm.com/docs/en/SSTDPP_1.10/investigator/investigator_intro.html). | true |
Documentation
Documentation for IBM Pak® QRadar Pak® Suite for Security can be found at https://www.ibm.com/docs/en/cloud-paks/cp-security/1.10.