IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Interacting with Vendor APIs

    Posted Wed December 11, 2019 03:14 PM
    Has anybody had success with getting QRadar to interact with APIs like ProofPoint TAP or Office ATP, and pull their respective logs back into QRadar?

    ------------------------------
    Miguel Quinn
    ------------------------------


  • 2.  RE: Interacting with Vendor APIs

    Posted Thu December 12, 2019 12:35 PM
    Not sure if it's relevant, we have used the McAfee JDBC connector to good effect and also have Crowdstrike logging via their API.  Seems to work OK. We have not set up Proofpoint TAP yet, but it's on our agenda.

    ------------------------------
    _____________________
    Daniel Sichel
    ------------------------------



  • 3.  RE: Interacting with Vendor APIs

    Posted Thu December 12, 2019 02:17 PM
    Thanks for the feedback Daniel! Do you have a rough timescale at all and do you know if anything is being done for Office 365 ATP?


    ------------------------------
    Miguel Quinn
    ------------------------------



  • 4.  RE: Interacting with Vendor APIs

    Posted Fri December 13, 2019 10:05 AM
    I am sorry to say I have no idea what the IBM roadmap is for this. Perhaps an IBM person monitoring this thread can shed some light on this for you.

    ------------------------------
    _____________________
    Daniel Sichel
    ------------------------------



  • 5.  RE: Interacting with Vendor APIs

    Posted Fri January 03, 2020 12:38 PM
    Proofpoint recently built an app that integrates with QRadar that utilizes the API.   I pushed them very hard to build  it over the last year and finally got them and IBM to collaborate and get it built.  I don't believe it is GA yet...I have a copy via my Proofpoint rep but haven't been able to test yet because we haven't finished migrating to proofpoint managed services from our on-prem deployment.

    ------------------------------
    AJ Reeves
    ------------------------------