QRadar Incident Forensics installations

You can install IBM QRadar Incident Forensics as a stand-alone deployment or as a distributed installation.

For stand-alone deployments, install QRadar Incident Forensics Standalone (appliance type 6100) on a single appliance.

For distributed installations, install the QRadar Console (appliance type 3199) on one appliance and QRadar Incident Forensics Processor(appliance type 6000) on another appliance. After the installation, you deploy the QRadar Incident Forensics Processor as a managed host.

Use the following steps to guide you through the installation process.
Installation process overview. Click here to get information about system requirements Click here to get information about installing QRadar Console Click here to get information about installing QRadar Incident Forensics Click here to get information about deploying a QRadar Incident Forensics managed host Click here to get information about adding a packet capture devices