Deployment Architecture

Database Schema in Splunk Architecture - QRadar

Martint
Loves-to-Learn Lots

Hi all:
I hope you are well. I have a query and I don't know if this is the correct thread to do it, I hope so. I have a presentation of differentials with IBM Qradar and among some details that I found very interesting within the Battlecard found on the portal, I was struck by the fact that IBM QRadar is a Database-based SIEM solution (Legacy SIEM Solution ), therefore it was difficult for him to correlate historical data. Unlike splunk that if you can do it, it is because of its structure. Based on this, I have reviewed and Splunk also bases its structure on a database display where it stores the indexes, which is the SPLUNK_DB file. Considering this, both solutions do not handle an index storage deployment in Database? Why then the differentiation that one by its architecture is limited in the search for historical correlation? Could you give me some support on the detail of it?

distributed search

Beforehand thank you very much¡¡¡

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Video | Welcome Back to Smartness, Pedro

Remember Splunk Community member, Pedro Borges? If you tuned into Episode 2 of our Smartness interview series, ...

Detector Best Practices: Static Thresholds

Introduction In observability monitoring, static thresholds are used to monitor fixed, known values within ...

Expert Tips from Splunk Education, Observability in Action, Plus More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...