Deployment Architecture

Database Schema in Splunk Architecture - QRadar

Martint
Loves-to-Learn Lots

Hi all:
I hope you are well. I have a query and I don't know if this is the correct thread to do it, I hope so. I have a presentation of differentials with IBM Qradar and among some details that I found very interesting within the Battlecard found on the portal, I was struck by the fact that IBM QRadar is a Database-based SIEM solution (Legacy SIEM Solution ), therefore it was difficult for him to correlate historical data. Unlike splunk that if you can do it, it is because of its structure. Based on this, I have reviewed and Splunk also bases its structure on a database display where it stores the indexes, which is the SPLUNK_DB file. Considering this, both solutions do not handle an index storage deployment in Database? Why then the differentiation that one by its architecture is limited in the search for historical correlation? Could you give me some support on the detail of it?

distributed search

Beforehand thank you very much¡¡¡

Labels (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...