Qradar server monitoring
Posted: Fri Mar 17, 2017 4:56 pm
IBM has told us that they do not support installing an agent on their Qradar server so we have to monitor it via SNMP.
They state:
IBM Security QRadar uses the Net-SNMP agent, which supports various system resource monitoring MIBs. They can be polled by Network Management solutions for the monitoring and alerting of system resources.
So... I have been asked to monitor disk space and CPU load as a starting point. I understand this is a RHEL 6 server but needs to have firewalls allowed in. I am assuming UDP 161 should be allowed. Any other ports?
Any help creating the checks with MIBs would be appreciated.
They state:
IBM Security QRadar uses the Net-SNMP agent, which supports various system resource monitoring MIBs. They can be polled by Network Management solutions for the monitoring and alerting of system resources.
So... I have been asked to monitor disk space and CPU load as a starting point. I understand this is a RHEL 6 server but needs to have firewalls allowed in. I am assuming UDP 161 should be allowed. Any other ports?
Any help creating the checks with MIBs would be appreciated.