Products: QRadar Family Overview

Q1 Labs has obtained a unique position in the security information and event management (SIEM) market by redefining how organizations deliver centralized network security management.

Understanding that security management challenges vary from organization to organization, as well as within various industries, Q1 Labs provides flexible product offerings that allow customers to meet their individual security management and compliance requirements – both in physical and virtual environments.

Core to this flexibility are QRadar and QRadar SLIM, two solutions that provide a simple, scalable upgrade path which evolves as an organization's security management requirements grow. QRadar's modular approach provides for almost unlimited horizontal scalability through the addition of various plug-and-play appliances.

Additionally, Q1 Labs offers a free, log management virtual appliance, QRadar SLIM FE, along with various optional flow collectors, flow processors, and event processors as outlined below.

QRadar:

  • Q1 Labs' flagship solution, QRadar, provides an integrated network security framework that converges typically silo'd network and security information into a single, cohesive solution. QRadar's unique approach enables enterprise organizations to deliver an unparalleled set of network security management services, including: log management, threat management, and compliance management.

    QRadar also makes possible a repeatable security process to improve operational efficiencies, better protect IT assets from a complex landscape of threats, and assist meeting a wide array of regulatory mandates.


QRadar SLIM:

  • QRadar Simple Log and Information Management (SLIM) provides a comprehensive and turnkey log management solution for organizations of all sizes. Log management has emerged as a required part of delivering security best practices and meeting specific auditing and reporting requirements of government regulations, including: Payment Card Industry Data Security Standards (PCI-DSS), Sarbanes-Oxley (SOX), Health Insurance Portability and Accountability Act (HIPAA), North American Electric Reliability Corp. (NERC), Federal Energy Regulatory Commission (FERC), and the Federal Information Security Management Act (FISMA).

    A subset of the QRadar solution, QRadar SLIM can be upgraded to full-featured QRadar via a license key with no loss of data.


QRadar SLIM Free Edition:

  • QRadar SLIM Free Edition (FE) is a free, downloadable, log management and compliance product that provides organizations with visibility across their networks, data centers, and infrastructures. With QRadar SLIM FE, IT professionals can collect, analyze, report, and store network, host, server, application, and security event logs, via syslog, from any source, including a wide variety of routers, switches, and security devices. QRadar SLIM FE's advanced analytics quickly turn confusing events into useful results that meet specific regulatory requirements.


QFlow Collectors:

  • Q1 Labs offers a family of QFlow Collectors, optional appliances that can be used in conjunction with the QRadar 3100, that provide added security at critical points across the enterprise network for greater defense. QFlow Collectors offer a cost-effective solution for gathering the most sophisticated and actionable flow data available from a network.

    QFlow Collectors go beyond traditional flow-based data sources to enable Layer 7 (Application Layer) flow analysis and anomaly detection. Deep packet inspection and content capture identify and mitigate threats that can be missed by other security devices.


VFlow Collector:

  • Since virtual servers are just as susceptible to security vulnerabilities as physical servers, organizations today now must define and implement appropriate precautionary measures to protect their applications and data that reside on a virtualized server.

    With VFlow Collector for QRadar, IT professionals have increased visibility into the vast amount of business applications activity appearing across their virtual networks. VFlow Collector for QRadar helps organizations better identify these applications for security monitoring, application-layer behavior analysis, and anomaly detection. VFlow Collector for QRadar also enables operators to capture application content for deeper security and policy forensics.


Flow Processors and Event Processors:

  • Q1 Labs' various add-on Flow Processors and Event Processors are expansion appliances that provide distributed scalability for the processing of network and application flow data and network and security events. Pre-installed with QRadar software and a hardened operating system, these appliances provide simple deployment and improved security, all at a low total cost of ownership.


Related link:

QRadar Brochure: Network + Security = Business Control