The migration tools from QRadar to Panther work, but they're bare minimum. They got our historical alerts and basic rule logic moved over. That's it.
My main concerns:
* No automated mapping of QRadar custom properties to Panther log schema fields. Manual work required.
* The tool didn't account for QRadar's reference data. Had to rebuild our threat intel lists.
* Zero validation of detection parity post-migration. We had to run both platforms in parallel for a month to confirm.
Has anyone else done this migration? Specifically:
* Did you get a full pen test report on Panther's migration API before using it? We had to push for it.
* How did you handle the compliance gap? Our QRadar instance was ISO 27001 certified. Panther's SOC2 Type II wasn't enough for our internal audit team initially.
Trust but verify