IBM QRadar SOAR

IBM QRadar SOAR

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Create artifact mapping

    Posted Thu January 11, 2024 04:31 AM
    Edited by benlinux Thu January 11, 2024 09:06 AM

    Hello Experts,

    I want to create artifact mapping for some QRadar offense fields using the QRadar-SOAR plugin app, but the "+"  as shown  below seems not to create a new entry (Type, Value and Description).

    https://www.ibm.com/docs/en/qradar-common?topic=mapping-case-artifacts.

    Also, i have an offense field in QRadar "Mac Address", and I want to include this field as an artifact on SOAR , can I use the below entry to send this field as an artifact:?

    Type: Mac Address

    Value: {{offense.mac_address}}

    Description: Mac Address.

    This seems not to work for me. 

    Kindly assist



    ------------------------------
    benlinux
    ------------------------------



  • 2.  RE: Create artifact mapping

    Posted Fri January 12, 2024 10:02 AM



    ------------------------------
    benlinux
    ------------------------------



  • 3.  RE: Create artifact mapping

    Posted Mon January 15, 2024 04:19 AM

    Hello experts,

    I will appreciate help here.

    Thanks 



    ------------------------------
    benlinux
    ------------------------------



  • 4.  RE: Create artifact mapping

    Posted Mon January 15, 2024 09:45 AM
    Use first line


    ------------------------------
    BENOIT ROSTAGNI
    ------------------------------