Aricoma CDC Platform
With Aricoma CDC Platform, a hybrid multicloud platform powered by IBM’s next-generation technologies, you can choose, build, and integrate the best architecture and approach to address your security team’s most critical application, data, and workload security requirements.
Solution Description
- Backup Deletion – this script is designed for the automated deletion of backups in QRadar when disk usage exceeds 90%. The automation prevents outages caused by a lack of free disk space, ensuring smooth system operation. The script regularly monitors available capacity and, upon exceeding the set limit, begins safely removing old backups according to predefined rules.
- Monitoring Scripts – scripts for monitoring outages of individual QRadar components have functionalities for generating syslog messages or sending email notifications. Besides standard monitoring processes, they include oversight of QRadar elements and applications not covered by built-in monitoring mechanisms. This allows for more effective detection of outages and their rapid escalation. The monitoring also incorporates advanced correlation rules that track log increases for specific groups of log sources and rules for detecting other anomalies involving parsing and correlation. This solution provides a flexible tool for improving insight into QRadar operations and minimizing the risk of unexpected problems.
- Network Hierarchy – this script is custom-made for a customer and is used for parsing HTML exports of their wiki that contains information about the network hierarchy. The parsed data is then stored in a JSON file in the required format, which is compatible with QRadar. The script allows for full automation and currency of the Network Hierarchy in SIEM.
- Prophylaxis Script – this script facilitates and accelerates system prophylaxis. The user only needs to replace the SEC token and IP address according to the specific customer (variables qradar_url and token). The script displays available API options directly in the console, allowing for quicker implementation of controls and automatic report generation. If a specific API function is not offered, the script provides an alternative procedure or the required AQL queries.
- Rule Exporter – this script combines the functions of the perl script contentManagement.pl and allows for easier export of rules from QRadar. It simplifies rule management and saves administrators' time through a more efficient data processing method.
- VirusTotal Info – this script enriches reports and AQL queries with three additional pieces of information obtained from the VirusTotal platform. This enables faster and more accurate detection of potential threats. The integration results provide administrators with more information for decision-making during incident analysis.
Benefits
- Optimized Storage Management The Backup Deletion script automates the removal of old backups when disk usage exceeds 90%, thus preventing system outages due to insufficient disk space. This ensures the continuous operation of the QRadar system without manual intervention.
- Enhanced Monitoring and Alerting Monitoring Scripts improve the detection of outages in QRadar XDR components, generating syslog messages or sending email notifications for rapid response. By overseeing elements not covered by standard monitoring mechanisms, they allow for quicker identification and escalation of potential issues, reducing downtime.
- Improved Network Hierarchy Management The Network Hierarchy script automates the parsing of wiki HTML exports into QRadar-compatible JSON files. This ensures that the network hierarchy in the Security Information and Event Management (SIEM) system remains current and accurate without manual updates.
- Streamlined System Prophylaxis The Prophylaxis Script facilitates faster system health checks by displaying available API options directly in the console, allowing for quicker implementation of controls and automatic report generation. This script simplifies the process and reduces administrative overhead.
- Efficient Rule Management The Rule Exporter script simplifies the export and audit of rules from QRadar, combining functionalities to save administrators’ time with a more efficient data processing method. It allows for a more streamlined approach to managing rule-bases.
- Enhanced Threat Detection VirusTotal Integration provides additional information in reports and AQL queries, enriching the data with details from the VirusTotal platform. This enables faster and more accurate detection of potential threats, aiding administrators in making informed decisions during incident analysis.
DO NOT HESITATE TO
CONTACT US
Are you interested in more information or an offer for your specific situation?