6:27 is an important point. "The license file is applied after raw events are calculated and before coalescence... so let's be clear - events per second are calculated on raw events not coalesced. Coalescence happens after [in the pipeline]" It's great that your Windows events are coalescing down 90%. But QRadar isn't going to count those 10k eps of Windows event's you're getting as 1k. It's counting raw events off the wire.
this is a complicated question. The prior five videos on my site go a decent distant towards making those recommendations. But there are so many kinds of log sources that we need to play it by ear.
Ho we can create a dashboard for Events dropped at DLC , EP and EC in a multitenant Environment?
6:27 is an important point. "The license file is applied after raw events are calculated and before coalescence... so let's be clear - events per second are calculated on raw events not coalesced. Coalescence happens after [in the pipeline]" It's great that your Windows events are coalescing down 90%. But QRadar isn't going to count those 10k eps of Windows event's you're getting as 1k. It's counting raw events off the wire.
Do you have any links to more information about IBM moving QRadar licensing to a per server model?
Does IBM has security events/logs recommend for each log source type.
this is a complicated question. The prior five videos on my site go a decent distant towards making those recommendations. But there are so many kinds of log sources that we need to play it by ear.
@@mikewinkler4625 sure.. thanks for your videos