Deployment Architecture

Database Schema in Splunk Architecture - QRadar

Martint
Loves-to-Learn Lots

Hi all:
I hope you are well. I have a query and I don't know if this is the correct thread to do it, I hope so. I have a presentation of differentials with IBM Qradar and among some details that I found very interesting within the Battlecard found on the portal, I was struck by the fact that IBM QRadar is a Database-based SIEM solution (Legacy SIEM Solution ), therefore it was difficult for him to correlate historical data. Unlike splunk that if you can do it, it is because of its structure. Based on this, I have reviewed and Splunk also bases its structure on a database display where it stores the indexes, which is the SPLUNK_DB file. Considering this, both solutions do not handle an index storage deployment in Database? Why then the differentiation that one by its architecture is limited in the search for historical correlation? Could you give me some support on the detail of it?

distributed search

Beforehand thank you very much¡¡¡

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...