QRadar Performance Optimization for an Electric System Operator
Summary
A US electric system operator ran two IBM Security QRadar consoles to protect its extensive grid network, but with data flowing from many log and flow sources the SIEM systems risked event omission, low performance, and heavy reports. The operator adopted INNERLUXES's proprietary QRadar performance-monitoring tool, whose health-check report surfaced a clear list of rule, memory, log-source, audit, and EPS issues. INNERLUXES's security consultants prioritized the fixes, and the operator went on to scale to 16K EPS under a 12-month support package.
About the Customer
The Customer is a US non-profit electric system operator. It runs the state's bulk electrical grid, with more than 10,000 miles of high-voltage transmission and over 500 electric power generators, and also acts as an advisory body providing unbiased technical information on energy issues.
Two QRadar Consoles at Risk of Event Omission and Low Performance
The Customer's network processes large volumes of valuable data every day. To strengthen security across its extensive network, the Customer had purchased two IBM Security QRadar consoles handling 8K events per second (EPS) each. Because the SIEM systems had to process data from multiple log and flow sources, they risked security-event omission, low performance, and heavy reports. To maximize the return on the consoles, get the most from their operability and performance, and build up network protection, the Customer's security department adopted INNERLUXES's automated, off-the-shelf tool for monitoring the operability and performance of a QRadar SIEM deployment.
A Health Check That Pinpointed the Issues to Fix
Satisfied with a demonstration of the tool, the Customer requested a license key for a two-week trial. During the trial, the operator's security specialists generated a health-check report that highlighted a number of QRadar performance, log-quality, and tuning issues. To address them in time, the team used the option to send the health-check report to INNERLUXES's security consultants, who reviewed it and outlined the problems that most needed attention to boost the efficiency of the two QRadar systems:
- Large execution time of certain custom rules due to faulty logic.
- Data-integrity issues caused by disabled event-log hashing.
- A lack of free memory on the QRadar consoles.
- Log sources in an error or inactive state.
- Insufficient audit configuration, with many servers and switches generating too few event types.
- A large number of uncategorized events arriving via the SIM Generic log source.
- EPS spikes of 12-13K that exceeded the license limits.
A Scaled-Up Deployment and an Ongoing Support Package
- The positive trial experience persuaded the Customer to purchase two licenses with a combined capacity of 16K EPS.
- As part of a 12-month support package, INNERLUXES planned two custom features: an additional health marker indicating the inactive or error state of specific log sources, and the ability to set a threshold for the percentage of devices in an inactive or error state — for example, raising an alert when 10% of the log sources in question are in an error state.
Technologies and Tools
INNERLUXES's proprietary performance-monitoring tool for IBM Security QRadar SIEM.