<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk and QRadar integration in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-and-QRadar-integration/m-p/107218#M183339</link>
    <description>&lt;P&gt;Whether or not there is benefit in integrating, primarily has to do with how vested you are in the use of qradar but also in how you want to use your data.  The possibility for use cases, beyond what qradar can reasonably handle, is huge in Splunk.  Of course, I'm speaking of the core capabilities of Splunk and not just ES.&lt;/P&gt;

&lt;P&gt;Splunk is a platform and it does not require that your data be fully parsed when it is indexed, so unlike database driven SIEMs, data can be parsed at search-time, to accommodate different use cases.  In addition, data not relevant in a SIEM can be utilized in Splunk.&lt;/P&gt;</description>
    <pubDate>Wed, 21 Aug 2013 15:13:28 GMT</pubDate>
    <dc:creator>sbrant_splunk</dc:creator>
    <dc:date>2013-08-21T15:13:28Z</dc:date>
    <item>
      <title>Splunk and QRadar integration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-and-QRadar-integration/m-p/107213#M183334</link>
      <description>&lt;P&gt;Hello, &lt;BR /&gt;
I am interested in examples of integration of Splunk as data source to QRadar.&lt;BR /&gt;
May be somebody has any? What kind of data, in what format and what way have you sent to Qradar?&lt;BR /&gt;
Is it a complicated process?&lt;/P&gt;

&lt;P&gt;Thanks for any advice!&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2013 07:12:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-and-QRadar-integration/m-p/107213#M183334</guid>
      <dc:creator>andrey2007</dc:creator>
      <dc:date>2013-07-26T07:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk and QRadar integration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-and-QRadar-integration/m-p/107214#M183335</link>
      <description>&lt;P&gt;any luck on this one?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2013 18:46:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-and-QRadar-integration/m-p/107214#M183335</guid>
      <dc:creator>jaoui</dc:creator>
      <dc:date>2013-08-20T18:46:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk and QRadar integration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-and-QRadar-integration/m-p/107215#M183336</link>
      <description>&lt;P&gt;to my sorry, no(&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2013 06:53:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-and-QRadar-integration/m-p/107215#M183336</guid>
      <dc:creator>andrey2007</dc:creator>
      <dc:date>2013-08-21T06:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk and QRadar integration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-and-QRadar-integration/m-p/107216#M183337</link>
      <description>&lt;P&gt;This depends on what sort of integration you have in mind.  If you simply would like to forward data from Splunk to QRadar, then you have a number of options.  &lt;/P&gt;

&lt;P&gt;I'm not familiar with QRadar's method of data ingestion but I suspect it accepts syslog data, so that would be one (probably the easiest) option.  There are a number of ways to send the syslog.  It could be cloned and sent at the same time that Splunk indexes it, raw.  You could also setup a real-time search and send (as syslog) the results of the search, using the &lt;A href="http://apps.splunk.com/app/1009"&gt;Splunk Real-Time Output app&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2013 07:24:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-and-QRadar-integration/m-p/107216#M183337</guid>
      <dc:creator>sbrant_splunk</dc:creator>
      <dc:date>2013-08-21T07:24:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk and QRadar integration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-and-QRadar-integration/m-p/107217#M183338</link>
      <description>&lt;P&gt;Certainly now your answer is the most complete but i am interesting in use cases. As i know Qradar and splunk ES are quite equal products(SIEMs) and have the same reports. That is why it is interesting for me to know is any profit from such kind of integration.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2013 07:38:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-and-QRadar-integration/m-p/107217#M183338</guid>
      <dc:creator>andrey2007</dc:creator>
      <dc:date>2013-08-21T07:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk and QRadar integration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-and-QRadar-integration/m-p/107218#M183339</link>
      <description>&lt;P&gt;Whether or not there is benefit in integrating, primarily has to do with how vested you are in the use of qradar but also in how you want to use your data.  The possibility for use cases, beyond what qradar can reasonably handle, is huge in Splunk.  Of course, I'm speaking of the core capabilities of Splunk and not just ES.&lt;/P&gt;

&lt;P&gt;Splunk is a platform and it does not require that your data be fully parsed when it is indexed, so unlike database driven SIEMs, data can be parsed at search-time, to accommodate different use cases.  In addition, data not relevant in a SIEM can be utilized in Splunk.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2013 15:13:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-and-QRadar-integration/m-p/107218#M183339</guid>
      <dc:creator>sbrant_splunk</dc:creator>
      <dc:date>2013-08-21T15:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk and QRadar integration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-and-QRadar-integration/m-p/107219#M183340</link>
      <description>&lt;P&gt;I downvoted this post because app is no longer there&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2016 14:33:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-and-QRadar-integration/m-p/107219#M183340</guid>
      <dc:creator>kefoster</dc:creator>
      <dc:date>2016-07-27T14:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk and QRadar integration</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-and-QRadar-integration/m-p/107220#M183341</link>
      <description>&lt;P&gt;As stated, the Splunk real-time output app is no longer available. Here is the official guidance for forwarding data to another system: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Forwarddatatothird-partysystemsd&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2016 15:13:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-and-QRadar-integration/m-p/107220#M183341</guid>
      <dc:creator>sbrant_splunk</dc:creator>
      <dc:date>2016-07-28T15:13:24Z</dc:date>
    </item>
  </channel>
</rss>

