Top Secret

 View Only
  • 1.  Integration CA Compliance Event Manager & IBM QRadar?

    Broadcom Employee
    Posted Jun 25, 2018 04:19 AM

    Has anyone worked on integrating IBM QRadar with CA Compliance Event

    Manager? If yes, then can you please share the steps on the configurations we need to perform in the MF environment and IBM QRadar Console.

     

    Thanks!



  • 2.  Re: Integration CA CEM & IBM QRadar?

    Broadcom Employee
    Posted Jun 27, 2018 12:26 PM

    Giovanni, can you please confirm if this request is for Customer Experience Manager (APM) or the Mainframe product? This may have been posted to the wrong community. 



  • 3.  Re: Integration CA CEM & IBM QRadar?

    Broadcom Employee
    Posted Jun 27, 2018 06:23 PM

    As Giovanni stated "CA Compliance Event Manager" I will move this question from CA APM community to CA Mainframe Security community.



  • 4.  Re: Integration CA Compliance Event Manager & IBM QRadar?

    Broadcom Employee
    Posted Jun 27, 2018 06:26 PM

    Changed thread title string "CA CEM" to "CA Compliance Event Manager"



  • 5.  Re: Integration CA Compliance Event Manager & IBM QRadar?

    Broadcom Employee
    Posted Jun 28, 2018 06:26 AM

    Well done Williams!

    Thank you



  • 6.  Re: Integration CA Compliance Event Manager & IBM QRadar?
    Best Answer

    Broadcom Employee
    Posted Jun 28, 2018 10:39 AM

    Hello,

     

    Please note that support for forwarding CA Compliance Event Manager events in real time to other SIEM platforms beyond Splunk was recently released as an Incremental Release PTF (previously available via APAR). Before this support, any feeding of events was accomplished in batch mode. Details about CA Compliance Event Manager Version 6.0 Incremental Release 4 (IR4) can be found at CA Support Online. Descriptions of the features released with IR4 are available in the product documentation.

     

    Below is some information from the CA Compliance Event Manager side to address the Mainframe-related portion of the question. Additional information from Communities members is appreciated. If no one posts additional information about the QRadar console-related portion of the question, I would defer you to the existing QRadar public domain information. There are some excellent videos available on YouTube, along with product documentation that describes the QRadar configuration that is necessary to accept the events. 

     

    There are two options for setting up the feed from CA Compliance Event Manager to QRadar: You can define CA Compliance Event Manager Policy Statements using our out-of-the-box sample Policy Action text in distributed (UNIX) syslog format, and forward them to QRadar’s syslog port (typically 514). Alternatively, you can copy the syslog format sample text and very easily convert it into LEEF format. When doing so, you can adjust the KEY VALUE pairs, where appropriate, to map to the predefined LEEF Event attributes. For more information about configuring SIEM in CA Compliance Event Manager, see the product documentation.

     

    Feel free to contact me directly for more details at James.Broadhurst@ca.com

     

    Thanks,



  • 7.  Re: Integration CA Compliance Event Manager & IBM QRadar?

    Broadcom Employee
    Posted Jun 28, 2018 12:38 PM

    James, well done; it is what the customer need!

    Thank you.