System requirements for Disconnected Log Collector

IBM Disconnected Log Collector is compatible with QRadar 7.3.1 or later.

System hardware

Table 1. System hardware requirements for Disconnected Log Collector
Requirement Description
Processor

Optimal: 4 CPU cores

Minimum: 2 CPU cores

Memory (RAM)

Optimal: 16 GB or more of available RAM.

Minimum: 8 GB or more of available RAM.

Disk space

100 GB or more of disk space.

Important: If you manage your partitions, assign the 100 GB of space to the /store partition. The /store directory must be either created on the root file system, which must be large enough to accommodate your Disconnected Log Collector instance, or you must create a separate /store file system.
Network adapter One or more network adapters.
Tip: Synchronize the time between the VM and host system to ensure consistent event times.

Operating system

Disconnected Log Collector requires one of the following Linux® operating systems:
  • Red Hat® Enterprise Linux (RHEL) V7.x or later
  • CentOS Linux V7.x or later
  • Ubuntu 22.04 or later
Disconnected Log Collector creates its own user account called dlc. It doesn't require any other user accounts on the system.

For more information about installing and configuring RHEL or CentOS Linux, see the RHEL documentation (https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/).

Public DNS

If you use a public DNS, and you use a local machine to host your Disconnected Log Collector, add the IP address and hostname of your Disconnected Log Collector in the /etc/hosts file on your Linux server. If you do not add the IP address and hostname to /etc/hosts, then your local Disconnected Log Collector machine is assigned a dynamic IP address.

Firewall ports

The syslog log source's target port and the destination port must be available and not blocked. By default, the target port is 1514 and the destination port is 32500 for both User Datagram Protocol (UDP) and Transport Layer Security over the Transmission Control Protocol (TLS over TCP).