IBM QRadar
  • 3 Minutes To Read
  • Print
  • Share
  • Dark
    Light

IBM QRadar

  • Print
  • Share
  • Dark
    Light

IBM QRadar is a Security Information and Event Management (SIEM) solution that enables security teams to detect, prioritize and response to threats across the enterprise.

Types of Assets Fetched

This adapter fetches the following types of assets:

  • Devices

Parameters

  1. Host Name or IP Address (required) - The hostname or IP address of the IBM QRadar server.
  2. User Name and Password (optional, default: empty) - The credentials for a user account that has the permissions to fetch assets.
NOTE

If API Token is not supplied, these fields are required.

  1. API Token (optional, default: empty) - An API Key associated with a user account that has the Required Permissions to fetch assets.
NOTE

If User Name and Password are not supplied, this field is required.

  1. Verify SSL (required, default: False) - Verify the SSL certificate offered by the value supplied in Host Name or IP Address. For more details, see SSL Trust & CA Settings.
    • If enabled, the SSL certificate offered by the value supplied in Host Name or IP Address will be verified against the CA database inside of Axonius. If the SSL certificate can not be validated against the CA database inside of Axonius, the connection will fail with an error.
    • If disabled, the SSL certificate offered by the value supplied in Host Name or IP Address will not be verified against the CA database inside of Axonius.
  2. HTTPS Proxy (optional, default: empty) - A proxy to use when connecting to the value supplied in Host Name or IP Address.
    • If supplied, Axonius will utilize the proxy when connecting to the value supplied in Host Name or IP Address.
    • If not supplied, Axonius will connect directly to the value supplied in Host Name or IP Address.
  3. HTTPS Proxy User Name (optional, default: empty) - The user name to use when connecting to the value supplied in Host Name or IP Address via the value supplied in HTTPS Proxy.
    • If supplied, Axonius will authenticate with this value when connecting to the value supplied in HTTPS Proxy.
    • If not supplied, Axonius will not perform authentication when connecting to the value supplied in HTTPS Proxy.
  4. HTTPS Proxy Password (optional, default: empty) - The password to use when connecting to the value supplied in Host Name or IP Address via the value supplied in HTTPS Proxy.
    • If supplied, Axonius will authenticate with this value when connecting to the value supplied in HTTPS Proxy.
    • If not supplied, Axonius will not perform authentication when connecting to the value supplied in HTTPS Proxy.
  5. For details on the common adapter connection parameters and buttons, see Adding a New Adapter Connection.

image.png

APIs

Axonius uses IBM QRadar REST API V11.0.

Required Permissions

The value supplied in API Token must have read access to devices.

To generate an API Token, use the Add Authorized Service window in IBM QRadar to add a new authorized service.

  1. On the navigation menu, click Admin.
  2. In the System Configuration section, click .
  3. Click Add Authorized Service.
  4. In the Service Name field, type a name for this authorized service. The name can be up to 255 characters in length.
  5. From the User Role list, select the user role that you want to assign to this authorized service. The user roles that are assigned to an authorized service determine the functions that this service can access on the IBM QRadar user interface.
  6. From the Security Profile list, select the security profile that you want to assign to this authorized service. The security profile determines the networks and log sources that this service can access on the QRadar user interface.
  7. In the Expiry Date list, type or select a date that you want this service to expire. If an expiry date is not required, select No Expiry.
  8. Click Create Service.

The confirmation message contains a token field that you must copy into your vendor software to
authenticate with QRadar.

Version Matrix

This adapter has only been tested with the versions marked as supported, but may work with other versions. Please contact Axonius Support if you have a version that is not listed and it is not functioning as expected.

Version Supported Notes
IBM QRadar V7.3.0 and higher
Was This Article Helpful?