Getting to know DLC
So far we have seen that to ingest data into QRadar, we need QRadar software to be installed on the VM or bare-metal servers, to have QRadar instances in the cloud, or to have QRadar appliances. But what if a customer does not want to invest in installing QRadar collector software or does not want to have an event collector? Can we still ingest events into QRadar? And if so, how?
Some customers may not have the bandwidth to procure QRadar boxes or maintain them. In this case, they can install an event collection function on a Linux machine that they already have running. This is not a dedicated event collector but a Linux box, which is installed with free software from IBM and is able to send a limited number of logs to QRadar deployment. The customer definitely needs the QRadar console in this case, but they do not require a separate event collector to collect events.
Some of the very high-security networks do not allow any inbound traffic. In such networks...