Detecção de SAP Enterprise Threat
O IBM QRadar DSM for SAP Enterprise Threat Detection coleta eventos de um servidor SAP Enterprise Threat Detection. O SAP Enterprise Threat Detection possibilita a inteligência de segurança em tempo real para ajudar a proteger contra ameaças de segurança cibernética e ajudar a garantir a prevenção de perda de dados.
Para integrar o SAP Enterprise Threat Detection ao QRadar, conclua as etapas a seguir:
- Se as atualizações automáticas não estiverem ativadas, baixe e instale a versão mais recente dos seguintes RPMs do IBM® em seu QRadar
Console:
- Protocolo-RPM Common
- RPM do Protocolo da API de Alerta do SAP ETD
- RPM do DSM SAP Enterprise Threat Detection
- Configure o QRadar para receber eventos do SAP Enterprise Threat Detection. Consulte os parâmetros de origem de log da API do SAP Enterprise Threat Detection Alert para SAP Enterprise Threat Detection.
- Configure o SAP Enterprise Threat Detection para se comunicar com o QRadar. Consulte a documentação do Enterprise ThreatMonitor Integration. (https://www.enterprise-threat-monitor.com/sap-qradar-enterprise-threat-detection-siem-integration/)
- Se o QRadar não detectar automaticamente a origem de log, inclua uma origem de log do SAP Enterprise Threat Detection no console do QRadar