印刷

QRadar SIEM Integration Prerequisites

This document includes information on the supported data collection methods, QRadar SIEM and VeloCloud software versions, QRadar SIEM Device Support Modules, and SIEM license requirements.

Data Collection Methods supported from Arista VeloCloud

VeloCloud consists of multiple services. In this guide, we will describe integration between the SD-WAN Edge appliances and QRadar SIEM, using Syslog and IPFIX Data. Other types of integrations might be delivered in the future. This guide will use the following network connectivity between Edges and QRadar Collector Nodes

Figure 1. Edge to QRadar Collector Node Connectivity

Software Version Matrix

The following table shows the versions of both VeloCloud and QRadar used in this guide:

Table 1. VeloCloud & QRadar Versions
VeloCloud & QRadar Versions Tested
QRadar 7.3.3 Field Patch 6 or higher
Log Source Management 7.0.1 or higher
VeloCloud Orchestrator 5.2.0.0 or higher
VeloCloud Edge 5.2.0.0 or higher

QRadar SIEM Device Support Module (DSM) for VeloCloud

The QRadar DSM (Device Support Module) software component lets QRadar collect data from various devices, such as firewalls, intrusion detection systems, and web proxies. The DSM provides a standardized interface for collecting data from these devices, which makes it easier for QRadar to ingest and analyze the data.

The QRadar DSM also has many features that help improve the performance of QRadar, such as data compression and filtering. This can help reduce the amount of data that QRadar needs to store and process, which can improve the system's performance.

For VeloCloud, you can download proprietary DSM modules from the Arista Developer portal or X-Force App Exchange. The DSM modules make sure that QRadar can format and display messages from VeloCloud services such as Edge devices. The DSM also contains event mappings to inject various VeloCloud events in a standard format message in your enterprise’s overall IT security ecosystem.

Note: You can reference the Version 1.7.0 of the QRadar SIEM Device Support Module here: QRadar SIEM Integration - Arista VeloCloud Edge Device Support Module v1.7.0.

QRadar SIEM License Requirements

You do not need a special license to receive events from VeloCloud. The integration will use both events per second (EPS) and flow per minute (FPM) licenses:
  • Edge logs: QRadar EPS (Events per Second) license required.
  • Edge Traffic Telemetry via IPFIX: QRadar FPM (Flows per Minute) license required.

Make sure the event collectors that collect logs and flow data have enough license allocations in QRadar. After you onboard the service, monitor the license requirements and adjust allocations as needed under (QRadar) Admin > System > System and License Management > License Pool Management .

See this KB Article for more information on event and flow capacity management.

..