Loading

IBM QRadar Integration for Elastic

Serverless Observability Serverless Security Stack 9.0.0

Version 0.1.0 Beta (View all)
Subscription level
What's this?
Basic
Level of support
What's this?
Elastic
Ingestion method(s) API

IBM QRadar is a Security Intelligence Platform that provides a unified architecture for integrating security information and event management (SIEM), log management, anomaly detection, incident forensics, and configuration and vulnerability management.

The IBM QRadar integration for Elastic allows you to collect logs using IBM QRadar API, then visualise the data in Kibana.

The IBM QRadar integration is compatible with QRadar API version 20.0.

This integration periodically queries the QRadar API to retrieve logs.

This integration collects log messages of the following type:

  • Offense: collect offense records from the Offenses and Rules endpoints, with rule data enriched into the offenses to provide additional context.

Integrating IBM QRadar with Elastic SIEM provides deep visibility into security offenses and their underlying context. Kibana dashboards track active and protected offenses, with metrics. Bar and pie charts highlight offense severity and status distribution, helping analysts quickly prioritize investigations.

Tables showcase the top contributing elements including rule types, assignees, log source types, log source names, and offense sources. A saved search of essential offense attributes IDs, severity, descriptions, categories, status, rules, assignees, activation and protection details ensures investigations are enriched with the necessary context.

These insights empower analysts to monitor offense activity, identify high-risk areas, and accelerate threat detection and response workflows.

This integration installs Elastic latest transforms. For more details, check the Transform setup and requirements.

To collect data through the IBM QRadar APIs, you need to create an Authorized Service Token with sufficient permissions. Authentication is handled using an Authorized Service Token, which serves as the required credential.

  1. Log in to the QRadar Console with an admin account.
  2. Go to the Admin tab, and in the User Management section, click Authorized Services.
  3. In the Authorized Services window, click Add Authorized Service.
  4. Fill in the following fields:
    • Service Name: Provide a descriptive name for this service.
    • User Role: Select the appropriate user role.
    • Security Profile: Assign the security profile to define which networks and log sources this service can access.
    • Expiry Date: Choose a date for the token to expire, or select No Expiry if indefinite use is required.
  5. Click Create Service.
  6. Select the row for the service you created, then copy the token string from the Selected Token field.
  7. Close the Authorized Services window.
  8. On the Admin tab, click Deploy Changes to apply the configuration.

For more details, see IBM Documentation.

This integration supports both Elastic Agentless-based and Agent-based installations.

Agentless integrations allow you to collect data without having to manage Elastic Agent in your cloud. They make manual agent deployment unnecessary, so you can focus on your data instead of the agent that collects it. For more information, refer to Agentless integrations and the Agentless integrations FAQ.

Agentless deployments are only supported in Elastic Serverless and Elastic Cloud environments. This functionality is in beta and is subject to change. Beta features are not subject to the support SLA of official GA features.

Elastic Agent must be installed. For more details, check the Elastic Agent installation instructions. You can install only one Elastic Agent per host.

  1. In the top search bar in Kibana, search for Integrations.

  2. In the search bar, type IBM QRadar.

  3. Select the IBM QRadar integration from the search results.

  4. Select Add IBM QRadar to add the integration.

  5. Enable and configure only the collection methods which you will use.

    • To Collect logs from QRadar API, you'll need to:

      • Configure URL and Authorized Service Token.
      • Adjust the integration configuration parameters if required, including the Interval, Batch Size etc. to enable data collection.
  6. Select Save and continue to save the integration.

  1. In the top search bar in Kibana, search for Dashboards.
  2. In the search bar, type IBM QRadar, and verify the dashboard information is populated.
  1. In the top search bar in Kibana, search for Transforms.
  2. Select the Data / Transforms from the search results.
  3. In the search bar, type ibm_qradar.
  4. Transform from the search results should indicate Healthy under the Health column.

For more information on architectures that can be used for scaling this integration, check the Ingest Architectures documentation.

These inputs can be used in this integration:

This integration dataset uses the following API:

This integration includes one or more Kibana dashboards that visualizes the data collected by the integration. The screenshots below illustrate how the ingested data is displayed.