SlideShare a Scribd company logo
1 of 22
www.scnsoft.com © 2017 ScienceSoft ®
Health Check Framework
for IBM QRadar SIEM
PRODUCT OVERVIEW
www.scnsoft.com © 2017 ScienceSoft ®
“SIEM products are complex and tend to become more so as vendors
extend capabilities. Vendors that are able to provide effective products
that users can successfully deploy, configure and manage with limited
resources will be the most successful in the market.”
Introduction
Gartner Magic Quadrant for Security Information and Event Management, 2016
Dr. Anton Chuvakin, Research VP at Gartner
“Measuring SIEM health and operations is still an emerging art.”
www.scnsoft.com © 2017 ScienceSoft ®
Executive Summary
Health Check Framework for QRadar SIEM (HCF) is a monitoring
instrument that allows for quick fine-tuning of QRadar SIEM deployments
Participates in “Ready for IBM Security Intelligence” program and IBM
AppExchange; used by Fortune 500 companies, government agencies,
MSP providers
Provides 60+ QRadar performance metrics and 25+ health markers for
on-the-fly performance assessment and configuration fine-tuning
Makes administration of QRadar SIEM deployments quicker and simpler,
cuts administration time, increases QRadar ROI and user satisfaction
www.scnsoft.com © 2017 ScienceSoft ®
HCF for QRadar SIEM
SITUATION: QRadar SIEM deployments suffer from:
 inefficient EPS license capacity utilization
 low log data quality and performance
 security events omission
 misfiring rules
 heavy rules and reports
SOLUTION: HCF for QRadar SIEM
 includes 60+ performance metrics, 25 Health Markers
 enables fast fine-tuning that increases ROI
 ensures that your QRadar SIEM runs efficiently and your
SOC team is available for important tasks
PROBLEM: vulnerable perimeter, costly SIEM administration, low SIEM ROI
www.scnsoft.com © 2017 ScienceSoft ®
Automated QRadar SIEM Monitoring
HCF for QRadar analyzes QRadar performance
within its environment and detects deviations
HCF for QRadar generates a detailed report and
notifies your security team about issues to attend to
HCF for QRadar suggests further remediation steps
to restore faultless operability of your SIEM system
www.scnsoft.com © 2017 ScienceSoft ®
HCF Report
Each report generated by HCF for QRadar
contains a detailed analysis with the following
performance indicators:
Console summary of the system’s state
(e.g. number of active log sources and
assets, storage and memory available,
top 10 unique offences)
Log sources statistics
Events and rules
EPS and FPM statistics
Data quality, etc.
www.scnsoft.com © 2017 ScienceSoft ®
HCF Report: Console Summary
Console Summary provides a dynamic view of the system performance
and enables stakeholders to respond to offenses nearly in real time
www.scnsoft.com © 2017 ScienceSoft ®
HCF Report: Log Sources
This report section provides a holistic view of active, inactive, disabled, last
added, deleted, modified log sources and protocol configuration errors
www.scnsoft.com © 2017 ScienceSoft ®
HCF Report: Events and Rules
Events and Rules show how fast correlation rules are executed, their
response time, the number of responses per correlation rule, as well as
reveal average and peak EPS from log within a specified timeframe, etc.
www.scnsoft.com © 2017 ScienceSoft ®
HCF Report: EPS and FPM Statistics
EPS and FPM Statistics reflect the amount of events and flows processed
over a certain period of time, thus alerting security specialists when the
enabled licenses don’t match the real incoming amount of log data
www.scnsoft.com © 2017 ScienceSoft ®
HCF Report: Data Quality
Data Quality reports the quality of data received from various device
types / log sources and the amount of log events that are collected but are
not properly normalized and parsed by QRadar
www.scnsoft.com © 2017 ScienceSoft ®
Health Markers
HCF for QRadar summarizes the status of all the important QRadar metrics in
the form of 25 Health Markers. In case a marker shows Failed, HCF for
QRadar sends an automatic warning with the description and basic
recommendations for fixing the issue
www.scnsoft.com © 2017 ScienceSoft ®
Challenges Solved with HCF for QRadar
Unsupported and
uncategorized security events
Misconfigured, unsupported
or unidentified log sources
Inadequate/unsatisfactory
log and event data quality
Improperly fine-tuned
correlation rules
SIEM system overload
Ineffective EPS capacity
utilization
!
!
!
!
!
!
www.scnsoft.com © 2017 ScienceSoft ®
HCF Value for Security Teams
Better control of
QRadar deployments
Increased log
data quality
Improved EPS license
capacity utilization
Less manual
routine work
Host overload
protection
Prompt diagnostics of
security attacks and threats
www.scnsoft.com © 2017 ScienceSoft ®
HCF Value for Security Decision Makers
Improved visibility of security
events
Less time, efforts, budget spent on
QRadar maintenance/ tuning
Improved effectiveness of security
teams and SOCs
Efficient planning and management
of QRadar investments
Higher ROI from QRadar
SIEM
www.scnsoft.com © 2017 ScienceSoft ®
HCF Value for IBM Business Partners
Improved
performance of
QRadar consultants
Increased customer
satisfaction and reduced
customer attrition
New upsell
and cross-sell
opportunities
www.scnsoft.com © 2017 ScienceSoft ®
Integration into QRadar Console
To ensure a flexible setup and tuning of your HCF for QRadar, we created
Health Check Framework Manager
DOWNLOAD
The application is
validated by IBM and
available for download at
IBM Security App
Exchange
www.scnsoft.com © 2017 ScienceSoft ®
The plugin brings you information that
you would need to spend hours trying to
find in the complicated QRadar log files
A super-useful set of reports and
metrics for QRadar SIEM
What Our Customers & Partners Say
Dr. Anton Chuvakin,
Research VP at Gartner
“
Ricardo Reimao,
Cybersecurity specialist at QRadar Insights
“
“ “
www.scnsoft.com © 2017 ScienceSoft ®
More Information on HCF for QRadar
HCF for QRadar at IBM Security
App Exchange
Detailed description and sample
reports of HCF for QRadar
HCF for QRadar installation guide
HCF for QRadar on QRadar
Insights
www.scnsoft.com © 2017 ScienceSoft ®
Success Story
Customer
Solution
Tools & Technologies
One of the largest banks in North America providing
services to 15+ million clients. The company is in the
top 100 on the 2016 Forbes Global 2000 list
HCF for a Major North American Bank
ScienceSoft implemented Health Check Framework for
QRadar with the following characteristics:
• 40+ hosts
• 40,000+ log sources
• 2,500,000+ assets
• 15,000+ average EPS
• 60+ QRadar users
www.scnsoft.com © 2017 ScienceSoft ®
Key Facts about ScienceSoft
ScienceSoft is an IBM Silver Business Partner that has been working in the
Security Intelligence area since 2004 and has over 30 IBM QRadar projects
behind its belt
450+
employees
Customers in 30+ countries,
including Fortune 500 companies
13 years in Information Security,
28 years in the IT market
www.scnsoft.com © 2017 ScienceSoft ®
Contact Us
SCIENCESOFT Finland
Myyrmäenraitti 2
01600 Vantaa, Finland
Phone: +358 92 3163070
Email: contact@scnsoft.fi
Web: www.scnsoft.com
SCIENCESOFT USA
5900 S. Lake Forest Dr., Suite 300
McKinney, TX 75070, USA
Phone: +1 214 306 68 37
Email: contact@scnsoft.com
Web: www.scnsoft.com

More Related Content

More from ScienceSoft

IT Solutions for Banking and Financial Services
IT Solutions for Banking and Financial ServicesIT Solutions for Banking and Financial Services
IT Solutions for Banking and Financial ServicesScienceSoft
 
Knowledge Management Solutions for Businesses
Knowledge Management Solutions for BusinessesKnowledge Management Solutions for Businesses
Knowledge Management Solutions for BusinessesScienceSoft
 
SharePoint Solutions to Build Environment for Effective Collaboration
SharePoint Solutions to Build Environment for Effective CollaborationSharePoint Solutions to Build Environment for Effective Collaboration
SharePoint Solutions to Build Environment for Effective CollaborationScienceSoft
 
Loyalty Program Management System for Retail
Loyalty Program Management System for RetailLoyalty Program Management System for Retail
Loyalty Program Management System for RetailScienceSoft
 
Software Testing Services
Software Testing ServicesSoftware Testing Services
Software Testing ServicesScienceSoft
 
Assortment optimization based on consumer clustering and behavior modelling
Assortment optimization based on consumer clustering and behavior modellingAssortment optimization based on consumer clustering and behavior modelling
Assortment optimization based on consumer clustering and behavior modellingScienceSoft
 
Automated Testing Services
Automated Testing ServicesAutomated Testing Services
Automated Testing ServicesScienceSoft
 

More from ScienceSoft (7)

IT Solutions for Banking and Financial Services
IT Solutions for Banking and Financial ServicesIT Solutions for Banking and Financial Services
IT Solutions for Banking and Financial Services
 
Knowledge Management Solutions for Businesses
Knowledge Management Solutions for BusinessesKnowledge Management Solutions for Businesses
Knowledge Management Solutions for Businesses
 
SharePoint Solutions to Build Environment for Effective Collaboration
SharePoint Solutions to Build Environment for Effective CollaborationSharePoint Solutions to Build Environment for Effective Collaboration
SharePoint Solutions to Build Environment for Effective Collaboration
 
Loyalty Program Management System for Retail
Loyalty Program Management System for RetailLoyalty Program Management System for Retail
Loyalty Program Management System for Retail
 
Software Testing Services
Software Testing ServicesSoftware Testing Services
Software Testing Services
 
Assortment optimization based on consumer clustering and behavior modelling
Assortment optimization based on consumer clustering and behavior modellingAssortment optimization based on consumer clustering and behavior modelling
Assortment optimization based on consumer clustering and behavior modelling
 
Automated Testing Services
Automated Testing ServicesAutomated Testing Services
Automated Testing Services
 

Recently uploaded

OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...Shane Coughlan
 
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...WSO2
 
WSO2Con204 - Hard Rock Presentation - Keynote
WSO2Con204 - Hard Rock Presentation - KeynoteWSO2Con204 - Hard Rock Presentation - Keynote
WSO2Con204 - Hard Rock Presentation - KeynoteWSO2
 
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...chiefasafspells
 
WSO2CON 2024 - How to Run a Security Program
WSO2CON 2024 - How to Run a Security ProgramWSO2CON 2024 - How to Run a Security Program
WSO2CON 2024 - How to Run a Security ProgramWSO2
 
tonesoftg
tonesoftgtonesoftg
tonesoftglanshi9
 
What Goes Wrong with Language Definitions and How to Improve the Situation
What Goes Wrong with Language Definitions and How to Improve the SituationWhat Goes Wrong with Language Definitions and How to Improve the Situation
What Goes Wrong with Language Definitions and How to Improve the SituationJuha-Pekka Tolvanen
 
%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein
%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein
%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfonteinmasabamasaba
 
%+27788225528 love spells in Toronto Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Toronto Psychic Readings, Attraction spells,Brin...%+27788225528 love spells in Toronto Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Toronto Psychic Readings, Attraction spells,Brin...masabamasaba
 
%in kempton park+277-882-255-28 abortion pills for sale in kempton park
%in kempton park+277-882-255-28 abortion pills for sale in kempton park %in kempton park+277-882-255-28 abortion pills for sale in kempton park
%in kempton park+277-882-255-28 abortion pills for sale in kempton park masabamasaba
 
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisamasabamasaba
 
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...masabamasaba
 
WSO2CON 2024 Slides - Open Source to SaaS
WSO2CON 2024 Slides - Open Source to SaaSWSO2CON 2024 Slides - Open Source to SaaS
WSO2CON 2024 Slides - Open Source to SaaSWSO2
 
Large-scale Logging Made Easy: Meetup at Deutsche Bank 2024
Large-scale Logging Made Easy: Meetup at Deutsche Bank 2024Large-scale Logging Made Easy: Meetup at Deutsche Bank 2024
Large-scale Logging Made Easy: Meetup at Deutsche Bank 2024VictoriaMetrics
 
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...masabamasaba
 
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisamasabamasaba
 
WSO2CON 2024 - API Management Usage at La Poste and Its Impact on Business an...
WSO2CON 2024 - API Management Usage at La Poste and Its Impact on Business an...WSO2CON 2024 - API Management Usage at La Poste and Its Impact on Business an...
WSO2CON 2024 - API Management Usage at La Poste and Its Impact on Business an...WSO2
 
AI & Machine Learning Presentation Template
AI & Machine Learning Presentation TemplateAI & Machine Learning Presentation Template
AI & Machine Learning Presentation TemplatePresentation.STUDIO
 
%in Rustenburg+277-882-255-28 abortion pills for sale in Rustenburg
%in Rustenburg+277-882-255-28 abortion pills for sale in Rustenburg%in Rustenburg+277-882-255-28 abortion pills for sale in Rustenburg
%in Rustenburg+277-882-255-28 abortion pills for sale in Rustenburgmasabamasaba
 
%in Stilfontein+277-882-255-28 abortion pills for sale in Stilfontein
%in Stilfontein+277-882-255-28 abortion pills for sale in Stilfontein%in Stilfontein+277-882-255-28 abortion pills for sale in Stilfontein
%in Stilfontein+277-882-255-28 abortion pills for sale in Stilfonteinmasabamasaba
 

Recently uploaded (20)

OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
OpenChain - The Ramifications of ISO/IEC 5230 and ISO/IEC 18974 for Legal Pro...
 
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
 
WSO2Con204 - Hard Rock Presentation - Keynote
WSO2Con204 - Hard Rock Presentation - KeynoteWSO2Con204 - Hard Rock Presentation - Keynote
WSO2Con204 - Hard Rock Presentation - Keynote
 
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
 
WSO2CON 2024 - How to Run a Security Program
WSO2CON 2024 - How to Run a Security ProgramWSO2CON 2024 - How to Run a Security Program
WSO2CON 2024 - How to Run a Security Program
 
tonesoftg
tonesoftgtonesoftg
tonesoftg
 
What Goes Wrong with Language Definitions and How to Improve the Situation
What Goes Wrong with Language Definitions and How to Improve the SituationWhat Goes Wrong with Language Definitions and How to Improve the Situation
What Goes Wrong with Language Definitions and How to Improve the Situation
 
%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein
%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein
%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein
 
%+27788225528 love spells in Toronto Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Toronto Psychic Readings, Attraction spells,Brin...%+27788225528 love spells in Toronto Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Toronto Psychic Readings, Attraction spells,Brin...
 
%in kempton park+277-882-255-28 abortion pills for sale in kempton park
%in kempton park+277-882-255-28 abortion pills for sale in kempton park %in kempton park+277-882-255-28 abortion pills for sale in kempton park
%in kempton park+277-882-255-28 abortion pills for sale in kempton park
 
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
 
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
 
WSO2CON 2024 Slides - Open Source to SaaS
WSO2CON 2024 Slides - Open Source to SaaSWSO2CON 2024 Slides - Open Source to SaaS
WSO2CON 2024 Slides - Open Source to SaaS
 
Large-scale Logging Made Easy: Meetup at Deutsche Bank 2024
Large-scale Logging Made Easy: Meetup at Deutsche Bank 2024Large-scale Logging Made Easy: Meetup at Deutsche Bank 2024
Large-scale Logging Made Easy: Meetup at Deutsche Bank 2024
 
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
 
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
 
WSO2CON 2024 - API Management Usage at La Poste and Its Impact on Business an...
WSO2CON 2024 - API Management Usage at La Poste and Its Impact on Business an...WSO2CON 2024 - API Management Usage at La Poste and Its Impact on Business an...
WSO2CON 2024 - API Management Usage at La Poste and Its Impact on Business an...
 
AI & Machine Learning Presentation Template
AI & Machine Learning Presentation TemplateAI & Machine Learning Presentation Template
AI & Machine Learning Presentation Template
 
%in Rustenburg+277-882-255-28 abortion pills for sale in Rustenburg
%in Rustenburg+277-882-255-28 abortion pills for sale in Rustenburg%in Rustenburg+277-882-255-28 abortion pills for sale in Rustenburg
%in Rustenburg+277-882-255-28 abortion pills for sale in Rustenburg
 
%in Stilfontein+277-882-255-28 abortion pills for sale in Stilfontein
%in Stilfontein+277-882-255-28 abortion pills for sale in Stilfontein%in Stilfontein+277-882-255-28 abortion pills for sale in Stilfontein
%in Stilfontein+277-882-255-28 abortion pills for sale in Stilfontein
 

Health Check Framework for IBM QRadar SIEM: Product Overview

  • 1. www.scnsoft.com © 2017 ScienceSoft ® Health Check Framework for IBM QRadar SIEM PRODUCT OVERVIEW
  • 2. www.scnsoft.com © 2017 ScienceSoft ® “SIEM products are complex and tend to become more so as vendors extend capabilities. Vendors that are able to provide effective products that users can successfully deploy, configure and manage with limited resources will be the most successful in the market.” Introduction Gartner Magic Quadrant for Security Information and Event Management, 2016 Dr. Anton Chuvakin, Research VP at Gartner “Measuring SIEM health and operations is still an emerging art.”
  • 3. www.scnsoft.com © 2017 ScienceSoft ® Executive Summary Health Check Framework for QRadar SIEM (HCF) is a monitoring instrument that allows for quick fine-tuning of QRadar SIEM deployments Participates in “Ready for IBM Security Intelligence” program and IBM AppExchange; used by Fortune 500 companies, government agencies, MSP providers Provides 60+ QRadar performance metrics and 25+ health markers for on-the-fly performance assessment and configuration fine-tuning Makes administration of QRadar SIEM deployments quicker and simpler, cuts administration time, increases QRadar ROI and user satisfaction
  • 4. www.scnsoft.com © 2017 ScienceSoft ® HCF for QRadar SIEM SITUATION: QRadar SIEM deployments suffer from:  inefficient EPS license capacity utilization  low log data quality and performance  security events omission  misfiring rules  heavy rules and reports SOLUTION: HCF for QRadar SIEM  includes 60+ performance metrics, 25 Health Markers  enables fast fine-tuning that increases ROI  ensures that your QRadar SIEM runs efficiently and your SOC team is available for important tasks PROBLEM: vulnerable perimeter, costly SIEM administration, low SIEM ROI
  • 5. www.scnsoft.com © 2017 ScienceSoft ® Automated QRadar SIEM Monitoring HCF for QRadar analyzes QRadar performance within its environment and detects deviations HCF for QRadar generates a detailed report and notifies your security team about issues to attend to HCF for QRadar suggests further remediation steps to restore faultless operability of your SIEM system
  • 6. www.scnsoft.com © 2017 ScienceSoft ® HCF Report Each report generated by HCF for QRadar contains a detailed analysis with the following performance indicators: Console summary of the system’s state (e.g. number of active log sources and assets, storage and memory available, top 10 unique offences) Log sources statistics Events and rules EPS and FPM statistics Data quality, etc.
  • 7. www.scnsoft.com © 2017 ScienceSoft ® HCF Report: Console Summary Console Summary provides a dynamic view of the system performance and enables stakeholders to respond to offenses nearly in real time
  • 8. www.scnsoft.com © 2017 ScienceSoft ® HCF Report: Log Sources This report section provides a holistic view of active, inactive, disabled, last added, deleted, modified log sources and protocol configuration errors
  • 9. www.scnsoft.com © 2017 ScienceSoft ® HCF Report: Events and Rules Events and Rules show how fast correlation rules are executed, their response time, the number of responses per correlation rule, as well as reveal average and peak EPS from log within a specified timeframe, etc.
  • 10. www.scnsoft.com © 2017 ScienceSoft ® HCF Report: EPS and FPM Statistics EPS and FPM Statistics reflect the amount of events and flows processed over a certain period of time, thus alerting security specialists when the enabled licenses don’t match the real incoming amount of log data
  • 11. www.scnsoft.com © 2017 ScienceSoft ® HCF Report: Data Quality Data Quality reports the quality of data received from various device types / log sources and the amount of log events that are collected but are not properly normalized and parsed by QRadar
  • 12. www.scnsoft.com © 2017 ScienceSoft ® Health Markers HCF for QRadar summarizes the status of all the important QRadar metrics in the form of 25 Health Markers. In case a marker shows Failed, HCF for QRadar sends an automatic warning with the description and basic recommendations for fixing the issue
  • 13. www.scnsoft.com © 2017 ScienceSoft ® Challenges Solved with HCF for QRadar Unsupported and uncategorized security events Misconfigured, unsupported or unidentified log sources Inadequate/unsatisfactory log and event data quality Improperly fine-tuned correlation rules SIEM system overload Ineffective EPS capacity utilization ! ! ! ! ! !
  • 14. www.scnsoft.com © 2017 ScienceSoft ® HCF Value for Security Teams Better control of QRadar deployments Increased log data quality Improved EPS license capacity utilization Less manual routine work Host overload protection Prompt diagnostics of security attacks and threats
  • 15. www.scnsoft.com © 2017 ScienceSoft ® HCF Value for Security Decision Makers Improved visibility of security events Less time, efforts, budget spent on QRadar maintenance/ tuning Improved effectiveness of security teams and SOCs Efficient planning and management of QRadar investments Higher ROI from QRadar SIEM
  • 16. www.scnsoft.com © 2017 ScienceSoft ® HCF Value for IBM Business Partners Improved performance of QRadar consultants Increased customer satisfaction and reduced customer attrition New upsell and cross-sell opportunities
  • 17. www.scnsoft.com © 2017 ScienceSoft ® Integration into QRadar Console To ensure a flexible setup and tuning of your HCF for QRadar, we created Health Check Framework Manager DOWNLOAD The application is validated by IBM and available for download at IBM Security App Exchange
  • 18. www.scnsoft.com © 2017 ScienceSoft ® The plugin brings you information that you would need to spend hours trying to find in the complicated QRadar log files A super-useful set of reports and metrics for QRadar SIEM What Our Customers & Partners Say Dr. Anton Chuvakin, Research VP at Gartner “ Ricardo Reimao, Cybersecurity specialist at QRadar Insights “ “ “
  • 19. www.scnsoft.com © 2017 ScienceSoft ® More Information on HCF for QRadar HCF for QRadar at IBM Security App Exchange Detailed description and sample reports of HCF for QRadar HCF for QRadar installation guide HCF for QRadar on QRadar Insights
  • 20. www.scnsoft.com © 2017 ScienceSoft ® Success Story Customer Solution Tools & Technologies One of the largest banks in North America providing services to 15+ million clients. The company is in the top 100 on the 2016 Forbes Global 2000 list HCF for a Major North American Bank ScienceSoft implemented Health Check Framework for QRadar with the following characteristics: • 40+ hosts • 40,000+ log sources • 2,500,000+ assets • 15,000+ average EPS • 60+ QRadar users
  • 21. www.scnsoft.com © 2017 ScienceSoft ® Key Facts about ScienceSoft ScienceSoft is an IBM Silver Business Partner that has been working in the Security Intelligence area since 2004 and has over 30 IBM QRadar projects behind its belt 450+ employees Customers in 30+ countries, including Fortune 500 companies 13 years in Information Security, 28 years in the IT market
  • 22. www.scnsoft.com © 2017 ScienceSoft ® Contact Us SCIENCESOFT Finland Myyrmäenraitti 2 01600 Vantaa, Finland Phone: +358 92 3163070 Email: contact@scnsoft.fi Web: www.scnsoft.com SCIENCESOFT USA 5900 S. Lake Forest Dr., Suite 300 McKinney, TX 75070, USA Phone: +1 214 306 68 37 Email: contact@scnsoft.com Web: www.scnsoft.com