Think 2019 / 6734 / February 14, 2019 / © 2019 IBM Corporation Please Note
Total Page:16
File Type:pdf, Size:1020Kb
QRadar 7.3.2 Feature Discussion - Matthew Carle QRadar Offering Management & Jonathan Pechta QRadar Support Content Lead Think 2019 / 6734 / February 14, 2019 / © 2019 IBM Corporation Please note IBM’s statements regarding its plans, directions, and intent are subject to change or withdrawal without notice and at IBM’s sole discretion. Information regarding potential future products is intended to outline our general product direction and it should not be relied on in making a purchasing decision. The information mentioned regarding potential future products is not a commitment, promise, or legal obligation to deliver any material, code or functionality. Information about potential future products may not be incorporated into any contract. The development, release, and timing of any future features or functionality described for our products remains at our sole discretion. Performance is based on measurements and projections using standard IBM benchmarks in a controlled environment. The actual throughput or performance that any user will experience will vary depending upon many factors, including considerations such as the amount of multiprogramming in the user’s job stream, the I/O configuration, the storage configuration, and the workload processed. Therefore, no assurance can be given that an individual user will achieve results similar to those stated here. 2 Notices and disclaimers © 2019 International Business Machines Corporation. No part of this Performance data contained herein was generally obtained in a document may be reproduced or transmitted in any form without controlled, isolated environments. Customer examples are presented as written permission from IBM. illustrations of how those U.S. Government Users Restricted Rights — use, duplication or customers have used IBM products and the results they may have disclosure restricted by GSA ADP Schedule Contract with IBM. achieved. Actual performance, cost, savings or other results in other Information in these presentations (including information relating to operating environments may vary. products that have not yet been announced by IBM) has been reviewed References in this document to IBM products, programs, or services for accuracy as of the date of initial publication and could include does not imply that IBM intends to make such products, programs or unintentional technical or typographical errors. IBM shall have no services available in all countries in which IBM operates or does responsibility to update this information. This document is distributed business. “as is” without any warranty, either express or implied. In no event, Workshops, sessions and associated materials may have been prepared shall IBM be liable for any damage arising from the use of this by independent session speakers, and do not necessarily reflect the information, including but not limited to, loss of data, business views of IBM. All materials and discussions are provided for interruption, loss of profit or loss of opportunity. IBM products and informational purposes only, and are neither intended to, nor shall services are warranted per the terms and conditions of the agreements constitute legal or other guidance or advice to any individual participant under which they are provided. or their specific situation. IBM products are manufactured from new parts or new and used parts. It is the customer’s responsibility to insure its own compliance In some cases, a product may not be new and may have been previously with legal requirements and to obtain advice of competent legal counsel installed. Regardless, our warranty terms apply.” as to the identification and interpretation of any relevant laws and Any statements regarding IBM's future direction, intent or product regulatory requirements that may affect the customer’s business and plans are subject to change or withdrawal without notice. any actions the customer may need to take to comply with such laws. IBM does not provide legal advice or represent or warrant that its services or products will ensure that the customer follows any law. Think 2019 / 6734 / February 13, 2019 / © 2019 IBM Corporation 3 Notices and disclaimers continued Information concerning non-IBM products was obtained from the IBM, the IBM logo, ibm.com and [names of other referenced IBM suppliers of those products, their published announcements or other products and services used in the presentation] are trademarks of publicly available sources. IBM has not tested those products about this International Business Machines Corporation, registered in many publication and cannot confirm the accuracy of performance, jurisdictions worldwide. Other product and service names might compatibility or any other claims related to non-IBM be trademarks of IBM or other companies. A current list of IBM products. Questions on the capabilities of non-IBM products should be trademarks is available on the Web at "Copyright and trademark addressed to the suppliers of those products. IBM does not warrant the information" at: www.ibm.com/legal/copytrade.shtml. quality of any third-party products, or the ability of any such third-party . products to interoperate with IBM’s products. IBM expressly disclaims all warranties, expressed or implied, including but not limited to, the implied warranties of merchantability and fitness for a purpose. The provision of the information contained herein is not intended to, and does not, grant any right or license under any IBM patents, copyrights, trademarks or other intellectual property right. Think 2019 / 6734 / February 13, 2019 / © 2019 IBM Corporation 4 Contents Part 1: Platform Updates 06 Part 2: Usability Enhancements 20 Introducing App Hosts 07 Admin Tab as a Favorite 21 Security Assertion Markup Language (SAML) 2.0 10 Rule Performance Visualization 22 Disconnected Log Collector (DLC) 11 Report Exports in CSV Format 25 Data Obfuscation for Multi-tenant Environments 12 Saved Search ‘Show AQL’ Option 26 VLAN Segmentation Multi-tenant Environments 13 Improved Management for Backup Files 27 Enhanced Clarity into MPLS Flows for IPFIX 14 User Management Facelift 28 Content Extension Enhancements 15 Reference Data Expiration Messages 30 Incremental Licensing 16 Additional Platform Updates 31 DrQ Health Check Framework 17 Installation and Virtual Machine Updates 19 Part 3: Data Ingestion 32 Traffic Analysis for Custom Log Sources 33 Traffic Analysis for Custom Log Sources 34 New structured data types - LEEF and CEF 35 Part 4: APIs 36 Selectable API versions interface 37 APIs in QRadar 7.3.2 38 Think 2019 / 6734 / February 13, 2019 / © 2019 IBM Corporation 5 Part 1 Platform Updates in QRadar 7.3.2 Think 2019 / 6734 / February 14, 2019 / © 2019 IBM Corporation 6 App Hosts (formerly QRadar App Nodes) 7.3.1 Deployments 7.3.2 Deployments Console Console What is the same? MH 1 From an architecture perspective, the App Host is MH 1 identical to the functionalist of an App Node. MH 2 • App Hosts be physical, virtual, or software. Installs MH 2 are completed with the QRadar 7.3.2 ISO file. • Purpose built to hosts all apps in the deployment App Host and remove processing load from the Console. App Node (appliance ID = 4000). App Node What is different? • App Nodes are no longer supported from 7.3.2 App Host has been rebuilt from the ground up to and forward. If an App Node is present during stabilize the whole process of running apps in QRadar. the 7.3.2 upgrade, users will be instructed to • Fully managed and patched as part of QRadar replace it with an App Host. Apps can be software update process. migrated after the App Host is installed. • Admins are no longer required to manage the OS. • A new 80% memory limitation is in place when • Supports standard deployment capabilities, such you migrate to an App Host. Available memory as backup & restore and High Availability. utilization was previously 100% for App Nodes. • Entitlement for App Nodes comes from Q1PD. Think 2019 / 6734 / February 13, 2019 / © 2019 IBM Corporation 7 Introducing App Host (formerly QRadar App Node) Where are app migrations managed? Admin > System and License Management Think 2019 / 6734 / February 13, 2019 / © 2019 IBM Corporation 8 Introducing App Host (continued) Apps that are migrated to the app host are moved and updated without impact to customer data. Apps that are being migrated to the App Host appliance cannot be used until the migration is complete. A progress bar indicates the current status of the app migration. NOTE: App Hosts have the same minimum system requirements as App Nodes. Think 2019 / 6734 / February 13, 2019 / © 2019 IBM Corporation 9 Security Assertion Markup Language (SAML) 2.0 What’s new? • QRadar starts supporting SAML 2.0 single sign on authentication (WEB SSO profile) from 7.3.2. • Easy to integrate with organization-wise single sign on solution in a standard way. • SAML 2.0 SSO web profile requires no direct server to server connection. • Fully support QRadar initiated or identity provider initiated single sign on/sign off. Why? Enterprise Single Sign-On, two/multi-factor authentication, CAC Cards. These are all solutions administrators look to in order to secure and manage authentication to enterprise infrastructure. QRadar 7.3.2 introduces support for SAML 2.0 to allow administrators to choose the best of breed technology for identity management and apply those same technologies to govern authentication and authorization within the QRadar platform. Think 2019 / 6734 / February 14, 2019 / © 2019 IBM Corporation New - Disconnected Log Collector (DLC) In the 7.3.2 timeframe we introduce the QRadar DLC, which mirrors a number of powerful What is in store for 2019? capabilities of our 15XX Event Collector and • Continuous delivery of protocols removes deployment restrictions. No longer does an administrator need full virtual infrastructure or • Configuration entirely from within QRadar even stand alone, purpose build appliance. A simple RPM install on existing RHEL or CentOS • Disconnected Log Collector (DLC) Chaining infrastructure can provide almost all of QRadar’s event collection capabilities. Uses a Universal DSM and the ‘IBM QRadar DLC Protocol’ when you configure log sources.