Configuring a QRadar Console on Google Cloud Platform
Configure an IBM® QRadar® SIEM Console on a Google Cloud Platform (GCP) instance by using the provided image.
Before you begin
The following procedure is for the configuration of an IBM QRadar 7.3.2 Console image, which has reached its End of Support. An IBM® QRadar® 7.4.3 Console image is not yet available. Once the image is installed, it should be upgraded to ensure that support is available. For information about upgrading to 7.4.3, see Upgrading QRadar SIEM.
You must acquire entitlement to a QRadar Software Node for any QRadar instance that is deployed from a third-party cloud marketplace. Entitlement to the software node should be in place before you deploy the QRadar instance. To acquire entitlement to a QRadar Software Node, contact your QRadar Sales Representative.
For any issues with QRadar software, engage IBM Support. If you experience any problems with GCP infrastructure, refer to GCP documentation. If IBM Support determines that your issue is caused by the GCP infrastructure, you must contact GCP for support to resolve the underlying issue with the GCP infrastructure.
You must use static IP addresses.
You cannot have more than two DNS entries. QRadar installation fails if you have more than two DNS entries in the /etc/resolv.conf file.
If you are installing a data gateway for QRadar on Cloud, go to Installing a QRadar data gateway in Google Cloud Platform (https://www.ibm.com/support/knowledgecenter/en/SSKMKU/com.ibm.qradar.doc_cloud/t_hosted_gcp_image.html).
- Create a project name that allows for a fully qualified domain name (FQDN) to be no more than 63
characters long. The FQDN consists of the deployment name followed by
-vm
, the zone, the region, the project name, and.internal
.For example, if your project name is abc-stq-xyz, the appliance deployment name is qr-con, the zone is us-east4-c, and the region is c, the FQDN is qr-con-vm.us-east4-c.c.abc-stq-xyz.internal. The zone can be between 10 and 25 characters long. Depending on the zone, this leaves somewhere between 25 and 40 characters to be split between your project name and your deployment name.
- In the project that you created in step 1, configure your network interface.
- Click . ©2019 Google LLC, used with permission. Google and the Google logo are registered trademarks of Google LLC.
- Click CREATE VPC NETWORK.
- Give your network a name, and configure the settings as needed. Set DNS server policy to No server policy.
- Click Create.
- Add an SSH key to the project if you haven't already done so. The key must be created for a user
called cloud-user.
- Click . ©2019 Google LLC, used with permission. Google and the Google logo are registered trademarks of Google LLC.
- Click SSH Keys.
- Click Edit.
- Click Add item.
- Enter an SSH key, followed by cloud-user.
- Click Save.
Procedure
What to do next
If you removed any DNS entries in /etc/resolv.conf, restore them.
The QRadar instance uses Coordinated Universal Time (UTC). You can change the time zone of the instance. For more information about changing the time zone, see Configuring system time.
This image does not receive automatic software upgrades. You must manually upgrade your system to keep it up to date. To receive QRadar upgrade notifications, see: Receiving QRadar update notifications
The QRadar Autoupdate server has changed since the release of QRadar 7.3.2 to update the auto update settings, see QRadar: Important auto update server changes for administrators (https://www.ibm.com/support/pages/qradar-important-auto-update-server-changes-administrators).