IBM Security Identity Manager

The IBM QRadar DSM for IBM® Security Identity Manager accepts audit, recertification, and system events from IBM Security Identity Manager appliances.

To integrate IBM Security Identity Manager with QRadar, complete the following steps:
  1. If automatic updates are not enabled, RPMs are available for download from the IBM support website (http://www.ibm.com/support). Download and install the most recent version of the DSM Common RPM on your QRadar Console.
  2. Configure your IBM Security Identity Manager to send events to QRadar.
  3. If QRadar does not automatically detect the log source, add a IBM Security Identity Manager log source on the QRadar Console.

To collect events with QRadar, you must have the IBM Security Identity Manager JDBC protocol that is installed, which allows QRadar to poll for event information in the ITIMDB database. IBM Security Identity Manager events are generated from the audit table along with several other tables from the database.

Before you configure QRadar to integrate with IBM Security Identity Manager, create a database user account and password in IBM Security Identity Manager for QRadar. Your QRadar user needs read permission for the ITIMDB database, which stores IBM Security Identity Manager events.

The IBM Security Identity Manager protocol allows QRadar to log in and poll for events from the database. Creating a QRadar account is not required, but it is suggested for tracking and securing your event data.

Note: Ensure that no firewall rules are blocking the communication between your IBM Security Identity Manager appliance and QRadar.