2

How QRadar Components Fit Together

After exploring the different QRadar components, let us now understand how they fit together. There are different ways to design a QRadar deployment, and it completely depends on the scope of the security operations that we intend to undertake. It depends on the number of endpoints, applications, users, and servers that we want to bring under the radar.

Therefore, in this chapter, we will explore two different types of deployments and why and when they are used. The following are the two types of QRadar deployments that we will discuss:

  • All-in-one deployment
  • Distributed deployment

We will also discuss the conditions under which the different components are added to the deployment.

All-in-one deployment ...

Get Building a Next-Gen SOC with IBM QRadar now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.