IBM Support

QRadar: Configuring 16xx/18xx Appliances in "Processing-Only" Mode

Question & Answer


Question

What is "Processing-Only" mode and how can this functionality be leveraged in my QRadar architecture?

Answer

Requirements

Administrators who want to configure an Event Processor or Combination Event/Flow Processor in "Event Processor Mode", there must be at least one Data Node appliance connected to the Event Processor to store event and flow data. There is no limit to the number of Data Nodes that can be assigned to an Event Processor.

What is Event Processor Mode?

Event Processor Mode is an advanced option that allows the Event Processor to dedicate CPU and memory resources to processing events and flow data. As the data is processed, the actual storage of the event or flow and searches are handled by the attached Data Node appliance. If more than one Data Node is assigned to the Event Processor, then the data is balanced between appliances and sent using round-robin format to each Data Node to equally distribute data.

Figure 1: An architecture example of how Processing-Only mode is used in a QRadar deployment.

Is this a common configuration?

No, most customers configure their Event Processors to process and store data, along with Data Nodes to expand on storage capabilities and search performance.

What are the benefits?

This feature allows administrators to have more performance for high EPS throughput and more granular control over their Event Processors functionality. If a Data Node is attached to the Event Processor, then you can configure Event Processor Mode. This allows the Data Node to be the primary appliance for storing and searching events and flows.

How to enable Event Processor Mode

    1. Log in to the QRadar User Interface.
    2. Click Admin tab > System and License Management icon.
    3. From Display, click Systems.

    4. Click the Event Processor

    5. Click Deployment Actions > Edit Host.

    6. Click Component Management.
    7. On the Component Configuration screen scroll to the bottom to Event Processor.
    8. Event Processor Mode.

      • Active means that the Event Processor will both Process and Store Events. The default is Active.
      • Processing-Only means that appliance resources are used for events and the storage and searching of the data is handled by the attached Data Nodes.
    9. Test Rules.
      • Locally - The rule is tested on the local Event Processor and not correlated across the deployment. The default is Locally.
      • Globally - Rule matches are sent to the Console for correlation.
    10. Click Save.

What happens if the Data Node goes offline?

When the Event Processor is configured for Processing-Only mode, a check is made to determine whether data can be written to the attached Data Node. If for some reason the Data Node is not online or available to receive data, the Event Processor will store events locally, as if it were in "Active" mode.


Where do you find more information?




[{"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Admin Console","Platform":[{"code":"PF033","label":"Windows"}],"Version":"7.2;7.3","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
16 June 2018

UID

swg21999409