The Black Cloud

Azure Local - Expanding the security ecosystem with IBM QRadar and Splunk

Azure Local is expanding its security ecosystem with integrations from industry leaders IBM and Splunk.

The official blog post touches on this for sure, but it is worth mentioning that it is very important for Azure Local customers who want to leverage existing security tools and capabilities without having to migrate to a different platform. More supportability is always a win in my book 🤣

Particularly vital for the Azure Local disconnected operations where the whole point of the solution is around security and compliance and those should help with that 😊

I found out about this from Thomas Maurer’s post:

LinkedIn post

Official blog post

Expanding the Azure Local Security Ecosystem with IBM QRadar and Splunk

Azure Local Security Ecosystem

What is IBM QRadar?

IBM QRadar is a Security Information and Event Management (SIEM) platform that provides real-time threat detection, analysis, and response capabilities. It helps organisations monitor and protect their networks and systems from security threats.

From their own website:

IBM® QRadar® is a threat detection and response solution designed to help security teams manage and respond to incidents more efficiently. It supports enterprise-scale operations and enables organizations to strengthen their security posture across core technologies.

The solution includes integrated capabilities for:

  • Endpoint security (EDR, MDR)
  • SIEM
  • SOAR

What is Splunk?

Splunk is a platform for observing and analysing machine-generated data. It helps organizations collect, index, and search vast amounts of data from various sources, including logs, metrics, and events, to gain insights and detect anomalies.

From their own website:

Though Splunk can refer to the company or its broader technology suite, it’s anchored by a unified core: the Splunk platform, delivered as Splunk Enterprise for on-premises environments and Splunk Cloud Platform for SaaS. Regardless of deployment, this powerful data platform helps organizations collect, analyze, and act on machine-generated data in real time, powering solutions across observability, security, IT operations, and business analytics.

Built on the unified Splunk platform, Splunk’s solutions — including Enterprise Security (SIEM), Observability Cloud, and SOAR — extend its core capabilities to meet specific security and IT needs. These aren’t standalone tools, but powerful use-case layers built directly on the platform.

Implementation guides?

NOTE

The cool thing for me is that both IBM and Splunk (should I be saying Cisco? 🤣) published their implementation guides on their websites already - both are linked in the original blog and below as well 😊

Fun fact: Splunk’s website still made a typo and put Azure local hosts in the header 🤣

Also, IBM actually has a full step by step guide whilst Splunk just pretty much refers you to Microsoft’s documentation for the syslog forwarding.

<< Previous Post

|

Next Post >>

#Blog #Azure Local #Security #IBM #QRadar #Splunk