Installing QRadar
The first step of QRadar installation is to understand which QRadar components will be needed in the deployment. We can always add processors and collectors when needed. However, we must start with the first step, which is requirement gathering. Let’s get started:
- Understand the amount of data in terms of EPS and FPM that will be ingested in QRadar. This will help us understand the number of processors required.
- Check whether the data has to be collected from geographically different regions, and also check the data privacy rules of the countries/states. This helps us to understand whether we will need processors or collectors. If the bandwidth is pretty low for the remote sites, we may also need Disconnected Log Collector (DLC).
- As per the EPS and FPM, ensure that hardware and software requirements are met. Ensure that the machine has enough memory, CPU, and storage before starting the installation.
- Understand the data retention policy...