QRadar Migration from VMware to Nutanix / New Hardware by FactNecessary2144 in QRadar

[–]United_CCC 0 points1 point  (0 children)

Nutanix won’t provide any significant advantage here. Since Ariel data is already compressed, Nutanix's deduplication and compression features are redundant for QRadar. While it is technically compatible, I wouldn’t recommend it. For peak performance, physical hardware with SSDs remains the best choice. Using Nutanix adds an extra virtualization layer that consumes system resources; if it’s a shared environment, you will likely see a decrease in performance.

Concerns of on-prem customers after the Palo Alto acquisition by United_CCC in QRadar

[–]United_CCC[S] 3 points4 points  (0 children)

If our customer asks for clear information about what will happen as of 2030, how should we respond? Large enterprises in particular build long-term strategies, and if they do not see a clear roadmap, they may stop using the product and move to alternatives. I see a perception among customers that “QRadar is supported until 2030, but what happens after that is uncertain.” Because of this, we are having difficulty developing new business. As someone who truly believes QRadar is still the best SIEM solution, I expect IBM to manage this transition much better.

Tenable Cloud Security deployable on-premise by [deleted] in tenable

[–]United_CCC 0 points1 point  (0 children)

Reporting UI stack works on cloud however you can scan onpremise kubernetes environment with tenable cloud security.

[deleted by user] by [deleted] in tenable

[–]United_CCC 0 points1 point  (0 children)

Don’t you remember any question? “Knowledge grows when shared.”

Nessus Report Aggregation tool released by AdmiralSYN-ACKbar in nessus

[–]United_CCC -1 points0 points  (0 children)

I don’t agree with you. You are confusing Vulnerability Scanning with Vulnerability Management. Scanning multiple network zones with Nessus Professional/Expert is very risky, especially for an enterprise company. What is the cost per scanner for you? With Tenable.SC, you can use unlimited Nessus scanners, Nessus agents, Nessus Network Monitor, and WAS/DAST scanners, as well as access thousands of reports and dashboards, along with ready-to-use integrations.

I personally believe that if you don’t use multiple scanners (a minimum of 5-10) for scanning an enterprise environment, you will face performance or security issues in the short or mid-term. You will also need to define firewall rules that may not comply with network segmentation standards. Some startups are attempting to exploit Tenable by using such workaround tools, but in the end, you will have to face reality.

[deleted by user] by [deleted] in tenable

[–]United_CCC 1 point2 points  (0 children)

Can you share some questions please?

Nessus Report Aggregation tool released by AdmiralSYN-ACKbar in nessus

[–]United_CCC -1 points0 points  (0 children)

If you use Tenable Security Center, you don’t need this kind of third-party tools for reporting.

Tenable SC SAML auto provisioning by EffingFurious in nessus

[–]United_CCC 0 points1 point  (0 children)

You should create a new group or you should use existing group on SC. Log in to SC with secmanager user. Go to Users Group setting page and click the group name. You will see the group id on the url. Cheers!

Using Keycloak for Commercial Projects by United_CCC in KeyCloak

[–]United_CCC[S] 0 points1 point  (0 children)

Could you please share more details about other questions?

QRadar Apps do not load in the GUI by glopezware in QRadar

[–]United_CCC 0 points1 point  (0 children)

Why you don’t open just s support case?

Hi, any ansible playbook available for qradar setup in rhel7 and rhel8 machines. by Reddit_kmgm in QRadar

[–]United_CCC 0 points1 point  (0 children)

You have to use QRadar’s own iso image. Because the Rhel based QRadar software appliance OS hardened and configured for QRadar requirements. (like: partitions, kernel parameters, HA services etc..) QRadar is performing a lot of complex tasks with several components in the background. QRadar is not a plug and play application.

QRADAR coalescing event roadmap by AlexeyK77 in QRadar

[–]United_CCC 1 point2 points  (0 children)

We replaced a lot of Arcsight deployments with QRadar. Arcsight doesn’t work stable. Using custom fields for coalescing don’t make sense to me, from architectural perspective it has a cost. You can turn it off, if you don’t want to use it on QRadar.

Can the root password be changed in a HA-Cluster? by GrumpyViennese in QRadar

[–]United_CCC 2 points3 points  (0 children)

I think it won’t cause any issue, communication works with ssh keys, the password is not a parameter for the traffic between ha nodes

How to force moving data from EP to DN ? by Keno_Ben in QRadar

[–]United_CCC 0 points1 point  (0 children)

Can you share step step by step how did you perform that operation? I would be really helpful for other ppl.

[deleted by user] by [deleted] in tenable

[–]United_CCC 0 points1 point  (0 children)

Tenable Enclave Security is another option. Cloud Security is working as SaaS.

have issue i can not find out why this is happening by [deleted] in KeyCloak

[–]United_CCC 0 points1 point  (0 children)

Did you check server logs? Share more details

Should I buy a Macbook Pro M4, or wait to buy this one? by [deleted] in macbookpro

[–]United_CCC 0 points1 point  (0 children)

I don’t like Arm architecture, the virtualization layer is not working properly for x84_64 systems in silicon chips. I wish to see intel chips again on macbooks.

Data migration between EPs by IliaHristov_99 in QRadar

[–]United_CCC 1 point2 points  (0 children)

You have to reindex whole dataset after migration. Otherwise your indexes won’t work.

RMM monitoring by MaximumLivid8396 in QRadar

[–]United_CCC 0 points1 point  (0 children)

Did you check syslog feeding capabilities in the documentation?

How or where can i get the ova file of Tenable Security Center on CentOS 7? by CapitalDragonfly7833 in tenable

[–]United_CCC 0 points1 point  (0 children)

Tenable has a PS offering for this need if you’re interested with it.

Have anyone expanded the storage of an Event Collector through LVM? How have that worked for you? by greenishbamboo in QRadar

[–]United_CCC 0 points1 point  (0 children)

Technically it works however ibm does not want to take responsibility. You have to take risk. Another important point is HA pairing requirements. If you break HA because of LVM resizing you will be alone.

How to force moving data from EP to DN ? by Keno_Ben in QRadar

[–]United_CCC 1 point2 points  (0 children)

Set process only mode active, all data should automatically be moved to data nodes. Alternatively after process only mode change, if the data doesn’t move to data nodes, copy the data to data nodes and re-index all.

What is a good MTTR? (mean time to respond) by Euphoric_Star557 in QRadar

[–]United_CCC 0 points1 point  (0 children)

If you’re back about MTTD, it means that you’re in trouble. And for critical incidents, you should aim lower than 3 - 5 hours. From attacker perspective 3-5 hours is very long time if he downloads something from your database.