Book description
The focus of this document is to demonstrate an early threat detection by using IBM® QRadar® and the Safeguarded Copy feature that is available as part of IBM FlashSystem® and IBM SAN Volume Controller. Such early detection protects and quickly recovers the data if a cyberattack occurs.
This document describes integrating IBM FlashSystem audit logs with IBM QRadar, and the configuration steps for IBM FlashSystem and IBM QRadar. It also explains how to use the IBM QRadar's device support module (DSM) editor to normalize events and assign IBM QRadar identifier (QID) map to the events.
Post IBM QRadar configuration, we review configuring Safeguarded Copy on the application volumes by using volume groups and applying Safeguarded backup polices on the volume group.
Finally, we demonstrate the use of orchestration software IBM Copy Services Manager to start a recovery, restore operations for data restoration on online volumes, and start a backup of data volumes.
Product information
- Title: Enhanced Cyber Resilience Threat Detection with IBM FlashSystem Safeguarded Copy and IBM QRadar
- Author(s):
- Release date: October 2021
- Publisher(s): IBM Redbooks
- ISBN: 9780738459875
You might also like
book
Securing Data on Threat Detection Using IBM Spectrum Scale and IBM QRadar: An Enhanced Cyber Resiliency Solution
Having appropriate storage for hosting business-critical data and advanced Security Information and Event Management (SIEM) software …
book
Securing Data on Threat Detection by Using IBM Spectrum Scale and IBM QRadar: An Enhanced Cyber Resiliency Solution
Having appropriate storage for hosting business-critical data and advanced Security Information and Event Management (SIEM) software …
book
Enhanced Cyber Security with IBM Spectrum Scale and IBM QRadar
Having appropriate storage for hosting business-critical data and advanced Security Information and Event Management software for …
book
Enhanced Cyber Resilience Solution by Threat Detection using IBM Cloud Object Storage System and IBM QRadar SIEM
This Solution Redpaper™ publication explains how the features of IBM Cloud® Object Storage System reduces the …