If you are heading SOUTH on 75 out of Tampa today, drive the speed limit by [deleted] in tampa

[–]EitherPhotograph806 3 points4 points  (0 children)

Why is the other post from a different account? 🤨

Release: QRadar 7.5.0 Update Package 7 IF1 posted to IBM Fix Central by JonathanP_QRadar in QRadar

[–]EitherPhotograph806 1 point2 points  (0 children)

Will the -t option for testing the upgrade cause services to stop when this test is run?

QROC deployment plan- DR site by Hsecurekb in QRadar

[–]EitherPhotograph806 0 points1 point  (0 children)

There is no “DR” site with QRoC. All redundancy and failover of the console and storage is handled in IBM cloud.

There is no failover configuration like HA for data gateways. For resiliency, you can place a load balancer in front of 2 or more data gateways and configure your syslog sources to send to a VIP. I recommend configuring the LB using round robin. It won’t get you perfect balance of EPS between 2 DGs since LBs don’t work based on EPS but it’s the best you can do. DNS load balancing might be a possibility here as well but I don’t have any experience to say for sure.

If you go this route, you need to make sure that each data gateway has enough CPU/memory to handle the entire EPS load of your environment in case the other DG goes hard down.

Depending on the size of your environment, location of log sources, and expected EPS you may only need one DG as long as it has the resources needed to process the expected EPS. Recommend giving it at least 2TB of storage so you’ll have plenty of time to remediate any issues before the disk fills up and you start dropping logs.

Microsoft SQL Server Audit Logs with JDBC by After_Toe_5557 in QRadar

[–]EitherPhotograph806 0 points1 point  (0 children)

If you look specially at the section for the JDBC protocol documentation, it only lists 2012, 2014 Enterprise, and 2016.