IBM QRadar
IBM QRadar is a Security Information and Event Management (SIEM) solution that enables security teams to detect, prioritize and response to threats across the enterprise.
Asset Types Fetched
- Devices, Users, Networks (if enabled in Advanced Settings)
Before You Begin
Ports
- TCP port 80/443
Authentication Method
- User Name/Password for Cloud
- API Token for on-prem
APIs
Axonius uses IBM QRadar REST API V20.0.
Permissions
The value supplied in API Token must have read access to devices.
-
Steps for creating an API token for IBM QRadar On Prem can be found here: Adding An Authorized Service
-
Steps for creating an API token for IBM QRadar On Cloud can be found here: Adding An Authorized Service Token
Both of these methods produce a token that is only displayed once. Please be sure to copy down the token at the end of the creation process as it can't be viewed again.
IBM QRadar On Cloud users may need to also whitelist the IP address of the Axonius instance. Instructions on doing so can be found here: Editing or deleting an allowlisted IP address
The following endpoints require permissions:
/api/asset_model/*- Requires Vulnerability Management or Assets permissions. Data returned is restricted based on the security profile assigned./api/system/*- Requires Admin permission and Admin security profile.
Connecting the Adapter in Axonius
To connect the adapter in Axonius, provide the following parameters:
Required Parameters
- Host Name or IP Address - The hostname or IP address of the IBM QRadar server.
- User Name and Password - The credentials for a user account that has the permissions to fetch assets.
Note
If API Token is not supplied, these fields are required.
- API Token - An API Key associated with a user account that has the Required Permissions to fetch assets.
Note
If User Name and Password are not supplied, this field is required.
Optional Parameters
- Verify SSL - Select whether to verify the SSL certificate of the server against the CA database inside of Axonius. For more details, see SSL Trust & CA Settings.
- HTTPS Proxy - Connect the adapter to a proxy instead of directly connecting it to the domain.
- HTTPS Proxy User Name - The user name to use when connecting to the value supplied in Host Name or IP Address via the value supplied in HTTPS Proxy.
- HTTPS Proxy Password - The password to use when connecting to the server using the HTTPS Proxy.
To learn more about common adapter connection parameters and buttons, see Adding a New Adapter Connection.
Advanced Settings
Note
Advanced settings can either apply to all connections for this adapter, or to a specific connection. Refer to Advanced Configuration for Adapters.
- Fetch Log Sources without Pagination (default: false) - Select this option to fetch all log sources at once without pagination. When enabled, this setting may assist Axonius in receiving log sources that were not received with pagination.
- Fetch All Asset Model Assets - Select this option to fetch all asset model assets as devices.
- Network Interface Enrichment - Select this option to parse network interface related fields.
- Fetch Networks - Select this option to fetch networks.
Note
To learn more about Adapter Configuration tab advanced settings, see Adapter Advanced Settings.
Version Matrix
This adapter has only been tested with the versions marked as supported, but may work with other versions. Please contact Axonius Support if you have a version that is not listed and it is not functioning as expected.
| Version | Supported | Notes |
|---|---|---|
| IBM QRadar V7.3.0 and higher |
Updated 1 day ago
