QRadar Network Insights installations on Microsoft Azure
Review the minimum system requirements.Ensure that the instance that you plan to install can support the flow inspection level that you want to achieve.
Install the QRadar
components by using the IBM
QRadar SIEM image on Microsoft Azure Marketplace.You must install a QRadar Console and a QRadar Network Insights managed host. Other managed hosts, such as flow processors, are optional. For information about how to install QRadar components on Microsoft Azure, see Configuring a Console on Microsoft Azure.
Add the QRadar Network Insights managed host to the QRadar
Console.
Configure
the flow sources.
Configure a traffic
mirroring session.
Verify that the deployment
is receiving flow data.
Deployment architecture

System requirements for QRadar Network Insights on Microsoft Azure installations
| Requirement | Value |
|---|---|
| Processor |
16 cores (minimum) on a single NUMA node Do not use virtual CPUs for QRadar Network Insights processing. |
| Memory |
64 GB (minimum) |
| Storage |
QRadar Network Insights requires two EBS
General Purpose SSD volumes:
The 98 GiB volume for the OS and software is configured automatically by the QRadar image. You must manually configure the additional 250 GiB volume for data. Warning: It is not possible to increase storage after installation.
|
| Networking |
QRadar Network Insights requires a minimum
of two NIC interfaces:
|
| Security Groups |
The management interface must have an assigned security group that includes rules to allow SSH, NetFlow, and messaging connections between the QRadar Network Insights host and the QRadar Console and any flow collectors or processors that might be installed. The monitoring interface must have an assigned security group that allows VXLAN traffic (UDP port 4789) from the mirror source. The Network ACL (VPC) level also must allow VXLAN traffic. |
To view the system requirements for other IBM QRadar virtual appliances, see System requirements for virtual appliances in the IBM QRadar Installation Guide.
Traffic mirroring
Before you configure traffic mirroring, you must have a QRadar Network Insights instance with an attached monitoring interface.
If you are using a third-party packet broker, it must support VXLAN encapsulated traffic exports to the QRadar Network Insights monitoring port.
For more information about setting up a virtual network TAP, see the Microsoft Azure website (https://learn.microsoft.com/en-us/azure/virtual-network/virtual-network-tap-overview).
Verifying that the QRadar Network Insights host is receiving flow data
Before you begin
You must configure a traffic mirroring session to forward traffic to the monitoring interface.