IBM QRadar SOAR

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Dashboard Interaction from Rest API

    Posted Mon September 21, 2020 11:18 AM
    Hi All,

    I am trying to get automated reports similar to that of the dashboards. I have read through the REST API documentation and cannot find anything related. 

    The report would only run once per month, so wouldn't be frequent. The only plausible way I can think of doing this is using the IncidentREST and parsing the JSON to check certain field values. We would be looking at a large query involving a large number of incidents.

    Regarding the above, I was hoping you could help me figure this out. I've included my questions below.

    1. Is there a better way of approaching this?
    2. Is it possible to make a request so that only specific fields return to avoid the return of massive JSON files?
    3. Can I specify a date range to return incidents over a specific time period?

    Thanks,
    Jack Gorman.


  • 2.  RE: Dashboard Interaction from Rest API

    Posted Mon September 28, 2020 01:50 PM
    At the moment, report scheduling is not possible.
    You can vote for the RFE on the subject : Ability to Schedule Custom Reports

    You could also use the Data Feeder integration to BI tools: Data Feeder on App exchange to export the data to an external BI tool and use this one to generated monthly report.

    ------------------------------
    BENOIT ROSTAGNI
    ------------------------------



  • 3.  RE: Dashboard Interaction from Rest API

    Posted Tue September 29, 2020 04:31 AM
    Edited by SIMON BRADISH Tue September 29, 2020 04:32 AM
    A replay on Data Feeder from @Raymond Suarez can be viewed here: Data Feeder Replay - Resilient Integration Update: Download to Deployment for Data Feeder

    ------------------------------
    SIMON BRADISH
    ------------------------------