IBM Security QRadar SIEM Integration for a Digital Identity Services Company
Summary
A US-based digital identity services company was preparing to launch a service that would process a large amount of sensitive data and needed a reliable SIEM to protect it. The Customer chose IBM Security QRadar SIEM (QRadar) and engaged INNERLUXES for additional configuration and fine-tuning — to leverage the platform's out-of-the-box functionality and to enable collection and processing of log events from custom applications.
About the Customer
The Customer is a US-based company that provides digital identity services, enabling its partners to verify the personal information of clients who want to obtain individual services and discounts.
The Challenge
Aiming to launch its digital identity service, the Customer was aware of the large amount of sensitive data it would process and need to protect from potential intruders. It looked for a reliable SIEM solution to ensure a proper level of data protection and, among multiple tools, chose IBM Security QRadar SIEM — a unified platform consolidating log events and network-flow data from multiple endpoints and applications. The Customer required additional QRadar configuration and fine-tuning to leverage the system's out-of-the-box functionality and to enable the collection and processing of log events from custom applications.
The Solution
INNERLUXES's experts started by analyzing the Customer's solution logic and IT infrastructure, which allowed them to assess the accuracy of QRadar's initial deployment. The analysis helped the SIEM team focus on two major points: first, they configured standard Device Support Modules (DSMs) to parse events received from multiple log sources and convert them to a standard taxonomy format; then they developed custom Log Source Extensions (LSXs) to integrate the platform with unsupported network objects represented by the Customer's proprietary applications.
Additionally, INNERLUXES's specialists carried out data normalization to ensure proper correlation of log events after their primary collection.
At the final stage, the SIEM team monitored the QRadar environment using INNERLUXES's proprietary QRadar health-check tool, developed to reveal performance issues and functional deviations of QRadar deployments. The monitoring let the experts verify whether the system processed logs from all connected log sources accurately, whether data quality met the established standards, whether the system correlated events into offenses correctly, and more.
The Results
- The professional QRadar configuration by INNERLUXES enabled the Customer to collect and process log data from unsupported applications, ensuring log-event visibility and the ability to detect potential breaches.
- The final monitoring of the QRadar environment with the health-check tool guaranteed the system's proper performance, minimizing the risk of overlooking critical security events.
Technologies and Tools
IBM Security QRadar SIEM, QRadar API, Regex, Bold.