QRadar Upgrade and Data Migration for a Global Distribution System Provider
Summary
A provider of a global distribution system for the travel industry was running an outdated IBM QRadar SIEM and needed it upgraded — without losing the year of data it had already collected. INNERLUXES scripted the migration to move that data and the log sources into the new system, stood up a high-availability console and added QRadar Network Insights, replaced the unsupported log exporter with WinCollect, and introduced a new Linux audit baseline that now filters two million noisy events a day, leaving the operator with a far cleaner, more reliable monitoring system.
About the Customer
The Customer is a provider of a global distribution system (GDS) for the travel and tourism industry, offering search, pricing, booking, and other processing services to travel companies.
An Outdated SIEM to Upgrade Without Losing Data
The Customer had an outdated version of IBM QRadar SIEM and engaged INNERLUXES to upgrade the legacy solution and migrate the data to the new system without losing the events collected over the past year.
Scripted Migration and a Hardened, Cleaner SIEM
INNERLUXES approached the upgrade so that continuity and data quality were protected at every step:
- Automated migration — the team first wrote a script to automate the data migration, greatly simplifying it and cutting the migration time.
- High-availability upgrade — installed the All-In-One QRadar SIEM Console in a high-availability (HA) cluster for continuous data collection and availability, and installed and configured the QRadar Network Insights (QNI) appliance to analyze the collected traffic flows.
- Full data and log-source transfer — all data collected over the past year was moved from the legacy SIEM into the new one, and the legacy log sources were migrated too so searches over the migrated data stayed continuous.
- Modern Windows collection — replaced the unsupported Adaptive Log Exporter (ALE) with the latest WinCollect Agent for collecting and processing Microsoft Windows security events, improving control and management of the collected data.
- Reduced noise — introduced a new audit baseline for Linux systems; the previous configuration produced huge volumes of noise that the correlation engine ignored, so the new baseline now filters 2,000,000 events a day, leaving staff with only the events needed for quality monitoring.
An Upgraded SIEM With Cleaner Monitoring
- The Customer received the upgraded IBM QRadar SIEM solution.
- The past year of legacy data, together with the event sources, was successfully transferred into the updated system.
- The extra tuning left the Customer with an improved event monitoring system.
Technologies and Tools
IBM QRadar SIEM 7.3.1, PostgreSQL, Python, shell scripts, Ansible, RegEx.