QRadar Risk Manager
QRadar Risk Manager (QRM) is another managed host that can be added to QRadar deployment. For each deployment, there can only be one QRM. QRM uses network topology information such as configuration backup from network devices, and vulnerability data from events to understand and prioritize the risks.
Figure 2.10 – Deployment with QRM
In Figure 2.10, we see that QRM is connected to network devices such as firewalls, intrusion prevention systems, and routers. QRM has multiple features that can make the life of QRadar admin easier. It provides a “discovery” feature. The admin will need to provide the IP address range. QRM will then start as a scan and will discover all the network devices in the subnet. Multiple IP address ranges can be provided, which would make the discovery of different network appliances possible.
Important note
QRM works on layer 3 of the Open Systems Interconnection (OSI) model.
Once...