SIEM Integration

What is SIEM?

Security Information and Event Management (SIEM) enables administrators to efficiently manage increasing security threats and comply with regulatory standards. SIEM assists in detecting, visualizing, scrutinizing, and responding to the various threats that risk your organization's data security.

Zoho eProtect enables seamless integration of its audit and threat activity logs with your SIEM solution for real-time security monitoring and action. 

QRadar Integration

IBM QRadar is a network security management solution that collects, correlates, and analyzes real-time audit log data to identify and address security threats. It helps organizations manage their network security by providing real-time monitoring, alerting for offenses, and responding to potential threats.

Prerequisites

  • Ensure that IBM QRadar is installed and operational.
  • Zoho eProtect supports sending event logs to QRadar exclusively through the HTTP Receiver protocol, which requires a valid SSL certificate issued by a Certificate Authority (CA). For more information, click here.
  • Ensure that your QRadar instance has an open inbound port, appropriate public IP address mapping, and a domain mapped to it with SSL/TLS properly configured to facilitate seamless data ingestion.

Steps to Integrate QRadar with Zoho eProtect

A. Configure HTTP Receiver in QRadar
  1. Log in to your organization's QRadar account.
  2. Navigate to the Log Source Management App to create a new HTTP Receiver log source.
  3. Create a new HTTP Receiver protocol log source in the New log source section.
  4. Deploy the newly created log source configuration.
B. Configure QRadar in Zoho eProtect
  1. Log in to Zoho eProtect.
  2. From the left pane, navigate to Logs and select SIEM Integration.
  3. Choose QRadar and click Configure.
  4. In the Selected Categories field, select the audit log categories you wish to monitor.
  5. In the URL field, enter the HTTPS Receiver Protocol Configuration URL from your QRadar account.
  6. Click the Add button.
  7. Enter the One-Time Password (OTP) sent to your QRadar account to confirm the addition.
C. Modify Audit Event Categories (Optional)
  1. To modify the audit event categories, add or remove events in the Selected Categories field.
  2. Click Update.
  3. Enter the OTP sent to your QRadar account to save the modifications.
D. Remove QRadar Configuration (If Needed)

To remove the QRadar configuration, click on Remove Configuration within the QRadar integration settings in Zoho eProtect.

By following these steps, you can successfully integrate Zoho eProtect with IBM QRadar, enabling centralized monitoring and management of your organization's security events.

PREVIOUS

UP NEXT