IBM QRadar SOAR

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Integration Qradar

    Posted Wed January 30, 2019 12:50 PM
    When we send an offense to Resilient, the "Owner" and "Created By" of the incident is "Rest API" (being the user that we generated for the integration).

    Is it possible that the "Owner" and "Created By" are the same operator that sent the offense?

    On the other hand, how could I send the "asset_name" field to generate a DNS type device with this data?

    ------------------------------
    Juan Cruz Del Col
    ------------------------------


  • 2.  RE: Integration Qradar
    Best Answer

    Posted Thu January 31, 2019 03:10 PM
    Is it possible that the "Owner" and "Created By" are the same operator that sent the offense?

    Yes, and No. when using Resilient QRadar Integration App to escalate offense to an incident,  there are two ways. automatically or manually.
    However, for automation escalation, the "created by" field always using API user(who you put in "Access tap" in Integration app). and for manual escalation, it required login information, the "Created by" is the user who login to Resilient,  and you can also specify the "owner" during creating an incident from an offense.

    On the other hand, how could I send the "asset_name" field to generate a DNS type device with this data?

    Yes,  but it required to create a customized template.

    ------------------------------
    Yu Zhang
    ------------------------------



  • 3.  RE: Integration Qradar

    Posted Thu January 31, 2019 03:20 PM
    Yu Zhang, Thank you very much for the quick answer.

    The scaling in my case is always "manual", I did not understand if I have to change or set both fields. Could you comment on how you would do it?

    "asset_name", in my custom template where and how do I add that data?

    ------------------------------
    Juan Cruz Del Col
    ------------------------------



  • 4.  RE: Integration Qradar

    Posted Thu February 07, 2019 03:02 PM
      |   view attached
    How could I send a custom field that is in the event within the offense I want to go to resilient?

    Ej:
    Offense ID 38029, contains 2 events. I select one of them and inside I have 3 fields "MWG_Dominio", "URL", "UrlHost",

    How to create 3 "URL" artifacts with each field?

    Within the template assign the fields, but I get an error:
    juan.c.delcol@set.ypf.com/service.svc/s/GetFileAttachment?id=AAMkAGU1MWI1NmNhLWMyNTktNGQyZC05MDAzLWE1NTY3MTFmNzI0NQBGAAAAAAAIE6SMZrKhRY4%2FuZJFgAvqBwArwgXH7Fl5Q637QGv8PF2yAAAAAAEJAAArwgXH7Fl5Q637QGv8PF2yAAAAD37DAAABEgAQAJfVZ7XuTcBDuQ7XhYC8MpQ%3D&X-OWA-CANARY=j5dS_CMHsU2s7XI3ihVDgRprBuw2jdYI3CYXl9UgHoR9dmAvskK2jwtwmuKaf0vLo8UbddBIgJw." class="img-responsive" data-mce-hlimagekey="da9dd460-29db-eec0-73e9-1af927acee4c" data-mce-hlselector="#MainCopy_ctl02_TinyMCEEditor_TinyMCEContent" title="Template Artifacts" alt="" data-skipsetcontent="true">

    ------------------------------
    Juan Cruz Del Col
    ------------------------------

    Attachment(s)

    txt
    Bloqueo de cuenta.txt   3 KB 1 version


  • 5.  RE: Integration Qradar

    Posted Thu February 07, 2019 09:58 PM
    The template only supports offense fields. The 3 fields "MWG_Dominio", "URL", "UrlHost" you listed are not offense fields so you can not add them to template directly.
    You can use Qradar function (https://exchange.xforce.ibmcloud.com/hub/extension/a9bcc3eaebf2a6efc04258b4964a48a4) to search Qradar and query events, then add the returned data as artifacts.

    ------------------------------
    LILY WANG
    ------------------------------



  • 6.  RE: Integration Qradar

    Posted Wed March 06, 2019 10:29 AM
    Is it possible to limit when an operator escalates an offense to a Resilient incident, another operator can not resubmit the same incident for the same offense?

    ------------------------------
    Juan Cruz Del Col
    ------------------------------



  • 7.  RE: Integration Qradar

    Posted Wed March 06, 2019 05:14 PM
    The integration process with check, if an offense has been escalated before it can not be escalated to a new incident again.

    ------------------------------
    LILY WANG
    ------------------------------



  • 8.  RE: Integration Qradar

    Posted Wed March 06, 2019 09:09 PM
    Will it be possible to limit it?

    There are many operators in the SOC and this usually happens.

    ------------------------------
    Juan Cruz Del Col
    ------------------------------