Detecção de SAP Enterprise Threat

O IBM QRadar DSM for SAP Enterprise Threat Detection coleta eventos de um servidor SAP Enterprise Threat Detection. O SAP Enterprise Threat Detection possibilita a inteligência de segurança em tempo real para ajudar a proteger contra ameaças de segurança cibernética e ajudar a garantir a prevenção de perda de dados.

Para integrar o SAP Enterprise Threat Detection ao QRadar, conclua as etapas a seguir:
  1. Se as atualizações automáticas não estiverem ativadas, baixe e instale a versão mais recente dos seguintes RPMs do IBM® em seu QRadar Console:
    • Protocolo-RPM Common
    • RPM do Protocolo da API de Alerta do SAP ETD
    • RPM do DSM SAP Enterprise Threat Detection
  2. Configure o QRadar para receber eventos do SAP Enterprise Threat Detection. Consulte os parâmetros de origem de log da API do SAP Enterprise Threat Detection Alert para SAP Enterprise Threat Detection.
  3. Configure o SAP Enterprise Threat Detection para se comunicar com o QRadar. Consulte a documentação do Enterprise ThreatMonitor Integration. (https://www.enterprise-threat-monitor.com/sap-qradar-enterprise-threat-detection-siem-integration/)
  4. Se o QRadar não detectar automaticamente a origem de log, inclua uma origem de log do SAP Enterprise Threat Detection no console do QRadar