cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
685
Views
0
Helpful
3
Replies

Qradar integration with pxGrid

umahar
Cisco Employee
Cisco Employee

Hi experts,

To my knowledge I haven't come across a pxGrid integration with Qradar or any other SIEM.

Can anyone please confirm ?

My understanding is syslogs can be directly sent over to Qradar, what added value would pxGrid integration offer ?

1 Accepted Solution

Accepted Solutions

Charlie Moreton
Cisco Employee
Cisco Employee

"Cisco ISE uses Cisco pxGrid technology to share contextual data with IBM QRadar SIEM. The integrated technology gives security analysts the ability to quickly and easily assess the significance of security events by correlating the expanded context with security alerts. The integration also provides QRadar with Cisco Rapid Threat Containment capability. It can then contain threats by using the network as an enforcer with VLANs or Cisco TrustSec® security groups."

https://www.cisco.com/c/dam/en/us/products/collateral/security/threat-response/solution-overview-c22-739546.pdf

"IBM Security QRadar SIEM integrates with AnyConnect NVM to form a solution that combines leadership IBM Security Intelligence capabilities with valuable contextual information about users, identities, privilege levels, and device types including mobile and BYOD."


https://blogs.cisco.com/security/pxgrid-keeps-growing

View solution in original post

3 Replies 3

Charlie Moreton
Cisco Employee
Cisco Employee

"Cisco ISE uses Cisco pxGrid technology to share contextual data with IBM QRadar SIEM. The integrated technology gives security analysts the ability to quickly and easily assess the significance of security events by correlating the expanded context with security alerts. The integration also provides QRadar with Cisco Rapid Threat Containment capability. It can then contain threats by using the network as an enforcer with VLANs or Cisco TrustSec® security groups."

https://www.cisco.com/c/dam/en/us/products/collateral/security/threat-response/solution-overview-c22-739546.pdf

"IBM Security QRadar SIEM integrates with AnyConnect NVM to form a solution that combines leadership IBM Security Intelligence capabilities with valuable contextual information about users, identities, privilege levels, and device types including mobile and BYOD."


https://blogs.cisco.com/security/pxgrid-keeps-growing

Jason Kunst
Cisco Employee
Cisco Employee

Thanks. I talked internally and a How to Guide for Qradar should be available in few weeks.