Setting up certificate-based authentication on QRadar
In TLS over TCP communication between IBM Disconnected Log Collector and IBM QRadar, certificate-based communication is used to establish a chain of trust in which hardware and software is validated from the end entity to the root certificate.
Before you begin
This setup is completed by IBM QRadar on Cloud DevOps team and is completed only for the first Disconnected Log Collector (DLC). Adding additional DLCs do not require a support ticket so long as you continue to use the same CA.
Important: If multiple Disconnected Log
Collectors exist in the environment,
perform the following steps only once on the QRadar system that the Disconnected Log
Collector connects to.