Installing QRadar Incident Forensics
Follow these steps to install an IBM® QRadar® Incident Forensics managed host in your QRadar environment.
For stand-alone deployments, install only the QRadar Incident Forensics Standalone component.
For distributed installations, install the QRadar Console on an appliance and install the IBM QRadar Incident Forensics managed host on another appliance.
Before you begin
Ensure that the following requirements are met:
The required hardware is installed.
A keyboard and monitor are connected using the VGA connection.
The activation key and all required license keys are available.
For more information, see Activation keys and license keys.
All appliances in the deployment have the same QRadar software version and fix level.
Deployments that use different versions of QRadar software are not supported.
Restriction: The following limitations apply to the deployment:
- Resizing logical volumes by using a logical volume manager (LVM) is not supported.
- In a high-availability (HA) deployment, you can install multiple QRadar Incident Forensics appliances, but you cannot configure the appliances as an HA cluster. Creating an HA cluster by using appliance type 6000 and type 500 is not supported.
Procedure
What to do next
Deploy the QRadar Incident Forensics managed host. For more information, see Adding a QRadar Incident Forensics managed host to QRadar Console.