IBM QRadar SOAR

IBM QRadar SOAR

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  We would like to confirm whether the following functionalities currently exist in SOAR or can be implemented using SOAR-provided APIs or server-side scripts

    Posted Fri April 18, 2025 11:22 AM

    We would like to confirm whether the following functionalities currently exist in SOAR or can be implemented using SOAR-provided APIs or server-side scripts:

    Script or API for checking SOAR service status and mitigating load

    A shell script that diagnoses the level of service load or issues and performs a service restart (limited to cases where restarting the service can resolve the issue).

    We would also like to include an email notification at the point of service restart, to log the restart time and confirm whether the service has returned to normal.

    Automatically restarting or retrying via SOAR or API

    While it is currently possible to configure cancellation based on certain conditions, restarting requires either manually recreating the incident or manually restarting the playbook.

    We would like to know if it's possible to implement automatic restarts via API or internal SOAR logic. In addition, we want to include a limit on the number of automatic retries and, when the retry threshold is exceeded, send an error message or notification email.

    Please confirm whether these functions are available or can be implemented with SOAR's existing capabilities.



    ------------------------------
    FDX Networks
    ------------------------------


  • 2.  RE: We would like to confirm whether the following functionalities currently exist in SOAR or can be implemented using SOAR-provided APIs or server-side scripts

    Posted 27 days ago

    I've responded to a similar query on an internal channel but for reference, perhaps SNMP monitoring might be useful

    https://www.ibm.com/docs/en/sqsp/51.0.0?topic=guide-monitoring-snmp



    ------------------------------
    Martin Feeney
    Product Manager, IBM Security QRadar SOAR
    martin.feeney@ie.ibm.com
    ------------------------------



  • 3.  RE: We would like to confirm whether the following functionalities currently exist in SOAR or can be implemented using SOAR-provided APIs or server-side scripts

    Posted 26 days ago

    I am correctly using the on-premises OVA.  Is there an SNMP MiB file on the OS?  If so, where is it located?



    ------------------------------
    Raymond Tam
    ------------------------------



  • 4.  RE: We would like to confirm whether the following functionalities currently exist in SOAR or can be implemented using SOAR-provided APIs or server-side scripts

    Posted 26 days ago

    You will need install and configure SNMP as per doc instructions, its not pre-installed.



    ------------------------------
    Martin Feeney
    Product Manager, IBM Security QRadar SOAR
    martin.feeney@ie.ibm.com
    ------------------------------