QRadar® Incident Forensics is available as a hardware, software or virtual appliance. Ensure that you have access to the following hardware components:
Uninterrupted Power Supply (UPS) for all systems that store data, such as QRadar Console, Event Processor components, or QRadar QFlow Collector components; Null modem cable if you want to connect the system to a serial console.
QRadar products support hardware-based Redundant Array of Independent Disks (RAID) implementations, but do not support software-based RAID installations.
OS: Red Hat Enterprise Linux (RHEL) Server 6. Prerequisite: IBM Security QRadar SIEM 7.2.2 and future fix packs
QRadar Incident Forensics is integrated into the IBM QRadar Security Intelligence Platform. For distributed installations, you can now add a QRadar Incident Forensics appliance (IBM Security QRadar Incident Forensics Processor) as a managed host to a QRadar appliance.
There is no longer a primary or secondary QRadar Incident Forensics node. Each QRadar Incident Forensics processor is managed by the QRadar console.