- 24 Mar 2022
- 3 Minutes to read
- Print
- DarkLight
- PDF
IBM QRadar
- Updated on 24 Mar 2022
- 3 Minutes to read
- Print
- DarkLight
- PDF
IBM QRadar is a Security Information and Event Management (SIEM) solution that enables security teams to detect, prioritize and response to threats across the enterprise.
Types of Assets Fetched
This adapter fetches the following types of assets:
- Devices
- Users
Parameters
- Host Name or IP Address (required) - The hostname or IP address of the IBM QRadar server.
- User Name and Password (optional, default: empty) - The credentials for a user account that has the permissions to fetch assets.
If API Token is not supplied, these fields are required.
- API Token (optional, default: empty) - An API Key associated with a user account that has the Required Permissions to fetch assets.
If User Name and Password are not supplied, this field is required.
- Verify SSL (required, default: False) - Verify the SSL certificate offered by the value supplied in Host Name or IP Address. For more details, see SSL Trust & CA Settings.
- If enabled, the SSL certificate offered by the value supplied in Host Name or IP Address will be verified against the CA database inside of Axonius. If the SSL certificate can not be validated against the CA database inside of Axonius, the connection will fail with an error.
- If disabled, the SSL certificate offered by the value supplied in Host Name or IP Address will not be verified against the CA database inside of Axonius.
- HTTPS Proxy (optional, default: empty) - A proxy to use when connecting to the value supplied in Host Name or IP Address.
- If supplied, Axonius will utilize the proxy when connecting to the value supplied in Host Name or IP Address.
- If not supplied, Axonius will connect directly to the value supplied in Host Name or IP Address.
- HTTPS Proxy User Name (optional, default: empty) - The user name to use when connecting to the value supplied in Host Name or IP Address via the value supplied in HTTPS Proxy.
- If supplied, Axonius will authenticate with this value when connecting to the value supplied in HTTPS Proxy.
- If not supplied, Axonius will not perform authentication when connecting to the value supplied in HTTPS Proxy.
- HTTPS Proxy Password (optional, default: empty) - The password to use when connecting to the value supplied in Host Name or IP Address via the value supplied in HTTPS Proxy.
- If supplied, Axonius will authenticate with this value when connecting to the value supplied in HTTPS Proxy.
- If not supplied, Axonius will not perform authentication when connecting to the value supplied in HTTPS Proxy.
- For details on the common adapter connection parameters and buttons, see Adding a New Adapter Connection.
APIs
Axonius uses IBM QRadar REST API V11.0.
Required Permissions
The value supplied in API Token must have read access to devices.
To generate an API Token, use the Add Authorized Service window in IBM QRadar to add a new authorized service.
- On the navigation menu, click Admin.
- In the System Configuration section, click .
- Click Add Authorized Service.
- In the Service Name field, type a name for this authorized service. The name can be up to 255 characters in length.
- From the User Role list, select the user role that you want to assign to this authorized service. The user roles that are assigned to an authorized service determine the functions that this service can access on the IBM QRadar user interface.
- From the Security Profile list, select the security profile that you want to assign to this authorized service. The security profile determines the networks and log sources that this service can access on the QRadar user interface. Under Log Source Groups -> Log Sources, ensure all relevant log sources are accessible to the service account.
- In the Expiry Date list, type or select a date that you want this service to expire. If an expiry date is not required, select No Expiry.
- Click Create Service.
The confirmation message contains a token field that you must copy into your vendor software to
authenticate with QRadar.
Version Matrix
This adapter has only been tested with the versions marked as supported, but may work with other versions. Please contact Axonius Support if you have a version that is not listed and it is not functioning as expected.
Version | Supported | Notes |
---|---|---|
IBM QRadar V7.3.0 and higher |