IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  integrate Kubernetes (K8s) with QRadar,

    Posted Mon February 03, 2025 07:49 AM

    I'm wondering if anyone has tried integrating Kubernetes (K8s) with QRadar. It would be great if someone could share a guide with us.



    ------------------------------
    Abdulrahman
    ------------------------------


  • 2.  RE: integrate Kubernetes (K8s) with QRadar,

    Posted Tue February 04, 2025 08:22 PM

    Hello Abdulrahman,

    please see this topic in the qradar documentation, hope this helps you further.

    https://www.ibm.com/docs/en/dsm?topic=configuration-kubernetes-auditing



    ------------------------------
    Erwin
    ------------------------------



  • 3.  RE: integrate Kubernetes (K8s) with QRadar,

    Posted Thu February 06, 2025 04:55 AM

    please be noted that is not work with us , as we did that before and not parsed probably 



    ------------------------------
    Abdulrahman alshalan
    ------------------------------



  • 4.  RE: integrate Kubernetes (K8s) with QRadar,

    Posted Thu February 06, 2025 07:13 PM

    Did you also install the Kubernetes custom properties extension?  https://www.ibm.com/docs/en/qradar-common?topic=extensions-kubernetes
    If that doesn't work, you could set property auto detection to On for a limited period and change them in the custom properties menu to your needs? 



    ------------------------------
    Erwin
    ------------------------------



  • 5.  RE: integrate Kubernetes (K8s) with QRadar,

    Posted Sun February 09, 2025 05:03 AM

    Could you please clarify more where is can download the Kubernetes custom properties extension , i didnot found any things 



    ------------------------------
    Abdulrahman alshalan
    ------------------------------



  • 6.  RE: integrate Kubernetes (K8s) with QRadar,

    Posted Mon February 10, 2025 06:11 AM

    is there any agent such as filebeat ?



    ------------------------------
    Abdulrahman alshalan
    ------------------------------



  • 7.  RE: integrate Kubernetes (K8s) with QRadar,

    Posted Mon February 10, 2025 08:42 AM

    kube & container content packs:
    https://exchange.xforce.ibmcloud.com/hub/extension/53af4c88c80e9fc8b0a2d8853d0f31ae
    https://exchange.xforce.ibmcloud.com/hub/extension/03b5e623d978dfa84b339dd6d38e02d5



    ------------------------------
    Erwin
    ------------------------------