IBM QRadar SOAR

IBM QRadar SOAR

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only

Sending Artifact Result to Custom linux box

  • 1.  Sending Artifact Result to Custom linux box

    Posted 01/07/24 10:30 PM

    To IBM qradar soar community,

    Currently I am implementing a solution for sending data from IBM qradar soar incident tab to a linux machine, however the current block is that from my knowledge in order to utilise playbook the target machine need to have some sort of API method (say for example running firewall block command in fortigate appliance require that fortigate appliance to have API method that can accept the query to the endpoint with some parameters).

    My current way to approach it is via soar api gateway and pull the data from the target machine. The only caveat for this method is that in order to run the script, the user will need to input the incident id value thus making it not fully automated. Also the problem with these method is that, it does not fulfill the criteria whereby I want the current incident open to send the artifact value processed into the target machine

    An alternative that I have think of is the usage of SFTP to send over the processed artifact data from the SOAR box to the target machine. The glaring problem is that I don't really know whether SOAR even store their processed artifact value within the SOAR box itself.

    Appreciate if anyone could guide me to certain way of implementing this step. Any information need, I will provide.

    Regards,

    Luqman



    ------------------------------
    Luqman Nur
    Techlab
    ------------------------------