IBM QRadar SOAR

IBM QRadar SOAR

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  SOAR - usage and value

    Posted 22 days ago

    Guys, I need to be able to get some report on SOAR usage.

    I know I could get something from System Settings --> License Information. But what I need is to identify the playbooks used in specific incidents.

    I know I could get information from Playbooks --> Playbooks Instances. But I can't see incident details or filter by incident type.

    I tried using the API and couldn't!

    Any suggestions?

    Has anyone experienced the need to be able to show and justify the use of SOAR to the CISO?



    ------------------------------
    Juan Cruz Del Col
    ------------------------------


  • 2.  RE: SOAR - usage and value

    Posted 21 days ago

    Soar isn't just about playbooks.

    How about some reports from the analytics dashboard showing incidents closed over time by type etc ?

    The playbook instances do show most used playbooks to highlight that side of soar.



    ------------------------------
    Martin Feeney
    Product Manager, IBM Security QRadar SOAR
    martin.feeney@ie.ibm.com
    ------------------------------



  • 3.  RE: SOAR - usage and value

    Posted 18 days ago

    Martin, thank you very much for the reply.
    I understand the point.


    But if I wanted to know, for example, when a malicious IP attack arrives (from different rules in Qradar):
    How much time do we save as a SOC operator by using the "IP Blocking in FW" playbook? This playbook includes:
    1. IP search in a whitelist.
    2. Query the IP reputation in three external sources.
    3. Query Qradar for source/destination IP events.
    4. Based on rules based on the information obtained, the block is sent in the FW or simply the activity is reported.
    5. Email is sent to management + FW admin about the tasks.

    All of this, without SOAR, can take an operator as quickly as 30 to 40 minutes during business hours. During off-duty hours, on-call personnel often have to be called, which can be costly, and the timescale could be longer than an hour.

    So, I'd like to be able to pull up a report that allows me to filter by incident type, severity, whether the incident is due to a radar violation, etc.

    I can't find a way to view this information, and I think it's valuable when we're asked every year... what did I earn with SOAR? "Time, money," how much? That's where we always have to justify...



    ------------------------------
    Juan Cruz Del Col
    ------------------------------



  • 4.  RE: SOAR - usage and value

    Posted 12 days ago

    Hey Juan,

    Sorry, out on vacation recently so just catching up on things.

    If there are specific automations you which to measure you could have the playbooks set values in a select field showing when they start/end, and then report on those times via time tracking as per;

    https://www.ibm.com/docs/en/sqsp/51.0.0?topic=guide-incident-layouts

    "When you create or edit a field of the type Select or Boolean, you can track the duration that the field spends on each value by selecting Track change times. You can use the tracking information in custom graphs or in an incident tab where the Timers Widget view is added. For more information, see the Creating custom incident graphs topic of the User Guide, or Displaying time tracking information in a tab."

    Does that help ?



    ------------------------------
    Martin Feeney
    Product Manager, IBM Security QRadar SOAR
    martin.feeney@ie.ibm.com
    ------------------------------