IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  QRadar API - Get the Event Details data from the offenses using API

    Posted 3 days ago

    Hello everyone, i have an question for using IBM QRadar API to get the detail event data from the Offense using API. The attachment is the step to get into the data i want to get using API, first of all we have to click one of the offense then click the event/flow count after that the pop up will show, then we edit search to add the Action-1 (custom) to the column and then search. Can i get the details data inside there using API? Whats the endpoint and the parameter to access inside there? Thank you

    for accessing data i want to get, we must get into the event details from the offense then click the event/flow count to show the pop up
    Here is the event details we want to get inside the Offense, before get into this section we using edit search to add the Action 1 (custom) to the column and then search. We want to get the Action-1 (custom) value and the others


    ------------------------------
    Albert Lius
    ------------------------------


  • 2.  RE: QRadar API - Get the Event Details data from the offenses using API

    Posted 2 days ago

    Albert, thanks for your enquiry. The simple answer is - yes you can! Most of your questions can be answered by the API documentation which is a live test environment inside the Qradar GUI. All GUI functions you are referring to are documented in the documentation. However there are a few challenges you have to workaround in your own program. The parameters are well documented there. The endpoint is whatever you want to use. The easiest way is to use curl for a basic test environment. You have to save your offense search 1st in order to get the results in the API. Please check the screens supplied for details.

    savesearch
    api search


    ------------------------------
    [Karl] [Jaeger] [#ibmchampion]
    [QRadar Specialist]
    ------------------------------