IBM QRadar

IBM QRadar

Join this online topic group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.


#Security
#QRadar
#SecuringhybridcloudandAI
 View Only

QRadar Insider : The monthly Newsletter For QRadar customers (August Edition)

By Poorva Thorat posted 8 days ago

  
Logo
   QRadar Insider     ISSUE 1 · AUGUST 2026

   The Monthly newsletter for QRadar customers                                                                                                                                                           

Welcome to the first edition of QRadar Insider. Here's what's new this month: a fresh industry recognition, a security enhancement you asked for, and a look at where we're taking cryptographic risk detection next with a seat at the table for you to help shape it. 

IN THIS ISSUE 

-> QRadar Named a G2 Leader  - recognized across 4 security categories. [2 min read] 

-> Customer Spotlight  - how Sutherland accelerated threat response with Automation and AI. [2 min read] 

-> Salesforce External Client App Support  - new authentication option, action optional. [1 min read] 

-> Support section  - one practical change you can make today. [3 min read] 

-> Quantum Risk Insights App  - help shape our newest app. [Action requested] 

-> Upcoming Events & Webinars  - save your seat. [30 sec skim] 

FEATURED STORY 

IBM QRadar Named a G2 Leader Across Four Critical Security Categories 

By Ashish Kothekar  |  IBM Security 

image

IBM QRadar SIEM has been recognized as a G2 Leader in four critical security categories - SIEM, User and Entity Behavior Analytics (UEBA), Network Traffic Analysis (NTA), and Incident Response. These rankings are driven entirely by verified customer reviews and market presence, reflecting the confidence security teams place in QRadar to detect, investigate, and respond to threats at scale. 

Customers consistently point to five reasons they stay with QRadar: 

  • Threat detection with high-fidelity analytics and correlation. 

  • Unified visibility across users, endpoints, networks, cloud, and hybrid environments. 

  • Faster investigations with actionable context and prioritization. 

  • Seamless integration with a broad, open security ecosystem. 

  • Improved analyst efficiency through AI-powered security operations capabilities. 

Read the full story >>

CUSTOMER SPOTLIGHT 

Sutherland: Accelerating Threat Response with Automation and AI in QRadar 

At Sutherland, we apply automation and AI to help companies deliver the best digital experiences to their customers. We wanted to apply the same technologies to cybersecurity. Using the automation and AI in IBM's QRadar Suite enables faster, more targeted, and more effective responses to threats."  

Pradnya Manwar 

Sr. Director 

Information and Cyber Security, Sutherland Global Services

Sutherland integrated IBM’s QRadar Suite to elevate their security operations by embedding advanced automation and AI capabilities. By streamlining threat workflows, the team achieved faster, more targeted, and highly effective incident responses across their enterprise environment. 

Read the full story >>

PRODUCT UPDATE 

QRadar Now Supports Salesforce External Client Apps 

By Sambhav Sahoo  |  IBM Security 

Based on direct customer requests, QRadar now supports Salesforce External Client Apps, with Client Credentials Flow available as an authentication option for Salesforce Security log sources. 

image


When configuring a Salesforce Security log source, customers can now choose the authentication method that matches their application: 

  • Password Authentication - the standard username/password method used for Connected Apps. 

  • Client Credentials Flow - standard client-secret authentication supporting both External Client Apps and Connected Apps. 

Existing Connected App customers can continue using Password Authentication with no changes required. This enhancement also helps customers prepare for the broader industry transition away from the Username-Password OAuth flow toward Client Credentials Flow. 

Read the full story >>

SUPPORT SECTION 

Quick Win: 

For overall QRadar deployment stability and optimal performance across both the event pipeline and search, it is important to ensure that raw events are assigned to the correct log source type for parsing. Correcting events that are assigned to the wrong log source type is one of the best regular tuning exercises to improve the health of the entire SIEM, not just parsing. 

Below is a quick way to identify these types of events and address them. 

In the AQL query below, we will use the Stored for Performance flag. Combined with the Unknown/Stored category filter, this will display all events from which an event ID and category cannot be extracted by the log source type with which the event is currently associated. 

How to do it: 

1. Run this AQL query in the log activity tab. The time range can be adjusted to cover a larger time frame or specific time frame. 

SELECT logsourcename(logSourceId) AS 'Log Source', SUM("eventCount") AS 'Event Count (Sum)', UniqueCount("collectorId") AS 'Event Collector (Unique Count)', UniqueCount(category) AS 'Low Level Category (Unique Count)', COUNT(*) AS 'Count' from events where ( category='10009' AND "storedForPerformance"='false' ) GROUP BY logSourceId order by "Count" desc last 60 minutes.

2. Review the top few log sources by opening the events and reviewing the payloads to see if they make sense for that log source type. Reference the DSM Guide if you are unsure whether the raw event structure is correct. One thing that can be helpful is testing these event payloads in the DSM Editor, either by selecting the events from Log Activity or by pasting the payload into the DSM Editor. From there, you can change the log source type to see if an event ID and category can be parsed out. 

 

3. If there is a log source type that is not used in the deployment, one of the best things to do is turn off auto-discovery in the DSM Editor under the Configuration tab. To preserve the performance of the SIEM, if a whole log source is not useful or tracking down the proper type will take time, disabling the log source is a great step. The events will be sent to the SIM Generic Log Source Type and will bypass any parsing logic. This will improve performance in the meantime, and the events can still be searched with Quick Filter within the retention period. 

 

INNOVATION SPOTLIGHT - WE WANT YOUR INPUT 

Can Your SIEM Tell You Where Quantum Risk Lives in Your Network? 

By Declan McNamara  |  IBM Security 

NIST finalized its first post-quantum cryptography (PQC) standards in 2024. For most security teams, that shifted the question from “should we prepare?” to “where do we start?” - and most don't have a live picture of which cryptographic algorithms are actually in use across their network. Certificate scanners show what's configured, not what's negotiated, which means cryptographic inventory is incomplete by definition. 

We're in the discovery phase of building the IBM QRadar Quantum Risk Insights App - a native app that would use QRadar Network Insights to inspect cryptographic metadata in live TLS, SSH, and RDP traffic, without decrypting payloads, and surface quantum-vulnerable algorithms as dedicated, fully contextualized offenses. 

Built for two audiences: 

Security analysts - triage-ready views of the most exposed assets and protocols, with drill-down to flow data. 

CISOs - trend dashboards and a readiness scorecard to track migration progress and report to the board. 

We're at the stage where customer input has the most influence on what gets built. If your organization is working through PQC planning, we want your view on three things: 

  • Priority protocols - TLS, SSH, or RDP: which traffic matters most for your environment first? 

  • Reporting needs - what would make the CISO readiness scorecard genuinely useful for board-level reporting? 

  • Workflow fit - should quantum-risk detections flow into existing offense workflows, or live in a dedicated view?

How to share your input: 

Early Access Program - anonymous, structured questions on the three areas above. 

UPCOMING EVENTS & WEBINARS

Mark Your Calendar 

24 SEPT 26

IBM QRadar Monthly - Upcoming New Features, Roadmap & Demo

Live webinar · 10 AM to 11 AM (ET) 

RESOURCES

Quick Links 

  • IBM Training -  to build and strengthen your cybersecurity skills
  • Ideas Portal - submit your innovation through IBM Ideas portal and help shape the future of cybersecurity

  • Subscribe - to our monthly newsletter to get it delivered straight to your inbox

IBM Security | QRadar 

LinkedIn   ·   Reddit   ·   IBM Community 

0 comments
57 views

Permalink