Acronis Cyber Protect Cloud integration with IBM QRadar
Features
The integration gives MSPs access to enhanced incident collection and response. Acronis alerts are displayed real-time in IBM QRadar SIEM, together with incidents and alerts coming from other integrated solutions.
With the ability to select which customers to send alerts to QRadar SIEM, MSPs can reduce noise and focus only on the incidents important for them. Moreover, MSPs can choose which of the 170 Acronis alerts to appear in the QRadar SIEM reports.
Acronis supports core event format - CEF (Common Event Format), enabling MSPs to work with the data sent by the integration out of the box. Alerts are pre-formatted on Acronis side and don't require MSP to create any additional rules on SIEM side. Integration is setup only by providing server and client certificates