Deployment Architecture

Database Schema in Splunk Architecture - QRadar

Martint
Loves-to-Learn Lots

Hi all:
I hope you are well. I have a query and I don't know if this is the correct thread to do it, I hope so. I have a presentation of differentials with IBM Qradar and among some details that I found very interesting within the Battlecard found on the portal, I was struck by the fact that IBM QRadar is a Database-based SIEM solution (Legacy SIEM Solution ), therefore it was difficult for him to correlate historical data. Unlike splunk that if you can do it, it is because of its structure. Based on this, I have reviewed and Splunk also bases its structure on a database display where it stores the indexes, which is the SPLUNK_DB file. Considering this, both solutions do not handle an index storage deployment in Database? Why then the differentiation that one by its architecture is limited in the search for historical correlation? Could you give me some support on the detail of it?

distributed search

Beforehand thank you very much¡¡¡

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...