IBM today announced a major new version of its QRadar SIEM (security information and event management) platform, rebuilt with a cloud-native architecture designed for the hybrid cloud era. The redesigned QRadar aims to maximize security analysts' productivity and make it easier to uncover threats.

IBM has been iterating on its QRadar SIEM technology since 2011, when it acquired Q1 Labs. In April of this year, IBM announced an updated QRadar security suite combining extended detection and response (XDR), security orchestration automation and response (SOAR) and artificial intelligence (AI) with SIEM. The new, cloud-native QRadar SIEM provides a different approach to deploying and scaling the technology, as well as providing even better visibility into hybrid environments.

QRadar is built with containers, microservices and Kubernetes on the Red Hat OpenShift platform to enhance flexibility and horizontal scaling. This allows auto-scaling of compute resources to match high event volumes in large hybrid environments.

[Related: CrowdStrike, Trend Micro, Bitdefender, Microsoft lead Forrester’s Wave for endpoint security]

“What we’re announcing is a completely new generation of QRadar SIEM, which we rebuilt from the ground up on a cloud-native architecture, while also introducing innovations that address the challenges of securing multicloud environments,” Chris Meenan, VP of product management for IBM Security, told SDxCentral. “This move is a critical step in the evolution of our broader QRadar Suite portfolio that we introduced in April. ”

How the cloud-native QRadar SIEM works

Meenan noted that when IBM first introduced its QRadar Suite earlier this year, it included a cloud-native log management capability, known as Log Insights.

The Log Insights tool is at the foundation of the new cloud-native SIEM. Meenan added that IBM has also developed a new user interface known as UAX — Unified Analyst Experience — that is also part of the new SIEM.

[caption id="attachment_135711" align="alignnone" width="1999"] An example of the QRadar SIEM dashboard. Image source: IBM Security.[/caption]

Meenan explained that the architecture for the new cloud-native SIEM is containerized software on Red Hat OpenShift, initially running on AWS. He added that IBM also plans to make it available for on-premises and other cloud deployments in 2024.

This isn't the first time IBM has offered QRadar in the cloud. To date, IBM has had a software-as-a-service (SaaS) offering for QRadar SIEM running on cloud infrastructure hosted by IBM. Whereas the new QRadar SIEM is built natively on Red Hat OpenShift.

“When it comes to the new cloud-native architecture for our SIEM, essentially you can think of this as a new engine for the car,” Meenan said. “The core analytics and detection capabilities build on what is currently offered with QRadar SIEM, but the underlying data foundation was rebuilt from scratch on Red Hat OpenShift and a high-performance data warehouse technology for greater scale, speed and resiliency.”

New query language boosts search and detection

Beyond the new architecture, there are a few additional search and detection features being introduced.

One such update for the new SIEM is the integration of a high-performance query language (KQL), which Meenan said provides a more simplified, user-friendly syntax that allows analysts to hunt for threats more quickly and easily.

“KQL is a very popular open-source language with a very large user community, so this helps alleviate some of the skills challenges when compared with solutions based on proprietary languages,” he said.

IBM is now also making use of the SIGMA open-standard shared language for detection rules. Meenan noted that this is the first time IBM is introducing SIGMA rules as the detection language for its SIEM. SIGMA is one of the most commonly used open-standard languages to share threat detection patterns and rules among the security analyst community.

“There are thousands of prebuilt detection rules available from sources such as SigmaHQ, and we have a dedicated IBM detection engineering team that will be vetting content from the community and creating new detections so that clients will have access to validated detections for the latest threats in a single click,” he said.

IBM's plan is to continue supporting innovation on both the classic and the new cloud-native editions of QRadar SIEM. That said, Meenan commented that IBM expects that the majority of its customers will eventually choose to transition to cloud native, as it provides a more flexible and scalable foundation for future demands.

“We have designed an extremely simple migration path that will make it easy for existing QRadar customers to transition to cloud native, which can also be done gradually over time,” he said.