Secured integration to the future

Secured integration to the future

IBM QRadar CE Update to Version 7.5.0

Майстер-клас: секрети випікання найсмачніших млинців!

05.07.2024

IBM QRadar SIEM is a software solution by IBM that excels at collecting and analysing security event logs and network communications from IT infrastructures. For decades, it has been considered the market leader, serving as a fundamental tool for building SOCs, security monitoring, and ensuring compliance with standards like PCI DSS, ISO 27001, NIST CSF, etc.
In May 2024, IBM released QRadar Community Edition 7.5.0. This full-featured, free version of QRadar SIEM, or QRadar CE, has data volume limitations and lacks vendor support. It is particularly useful for developers, security engineers, students, and small organisations that want to learn, create, and test solutions based on QRadar SIEM.

Key Limitations of QRadar Community Edition 7.5.0:

● Capable of processing up to 100 events per second (EPS) and up to 5000 network flows per minute (FPM).● Free licence valid for three months, renewable under the same conditions.● No support or warranty from IBM.
The previous version, QRadar Community Edition 7.3.3, had not been updated for several years and had become outdated compared to the corporate version of IBM QRadar SIEM. The updated IBM QRadar CE 7.5.0 is based on the corporate version and includes all enhancements implemented in the SIEM for corporate infrastructures.

Enhancements in QRadar CE 7.5.0 Compared to 7.3.3:

● Simplified deployment with support for installation from ISO files.● Transition from CentOS to Red Hat 8.8 OS, with updates included in the free SIEM CE licence.● Increased limit from 50 EPS to 100 EPS.● No restrictions on the number of Device Specific Modules (DSM).● It is possible to install applications on a separate QRadar App Host server.● Access to IBM X-Force AppExchange and application management is available through the integrated QRadar Assistant Manager.● Access to IBM X-Force Threat Intel.● Availability of historical correlation of events and support for SIGMA and YARA rules.● Ability to forward events from QRadar SIEM.● Technical documentation aligned with the corporate version of IBM QRadar SIEM.● Renewable free licence every three months.
The additional advantage for developers and engineers is the compatibility of applications and extension modules with the corporate version of IBM QRadar SIEM. The IBM QRadar CE licence does not cover additional functional servers within the SIEM deployment. However, Event Processors, QRadar Network Insights, Risk Manager, Event Collectors, and Data Nodes can be installed and tested under temporary licences.
Despite the lack of official vendor support, users can always seek assistance from the community or our experts to address their queries.

The highly anticipated IBM QRadar CE 7.5.0 update opens new opportunities for students and small organisations, granting them access to one of the most popular SIEM tools. This update will enhance the skills of cybersecurity professionals and help small organisations better protect their assets and monitor more events.

Useful Links:

● Product Page on the Manufacturer's Website: https://www.ibm.com/community/101/qradar/ce/
● IBM QRadar Forum on Reddit:https://www.reddit.com/r/QRadar/
● Official IBM Security Community Forum:https://community.ibm.com/community/user/security/communities/community-home/digestviewer