IBM QRadar SOAR

 View Only

 How to use PROXY settings on each call to restAPI function

Alejandro Siles's profile image
Alejandro Siles posted 09/28/26 03:31 PM

Hi,

I need to implement differents calls to restAPI function (from the REST API Functions for SOAR App) within my playbooks.

In some cases, the access to the service's API requires a proxy, while in others it does not. I haven't found any parameter that allows for this configuration.

Could anyone suggest a possible solution?

Regards

Alejandro

Yohji Amano's profile image
Yohji Amano

Hi Alejandro.

I'm not sure the following is the adequate for your case though.


How about trying 'manageAppHost proxy...' command to the AppHost where REST API function runs. It can configure http proxy(--http-proxy-url), https proxy(--https-proxy-url) and no_proxy(--no-proxy). You can configure the IPs which do not require proxy settings with no proxy.

ex.)

sudo manageAppHost proxy --http-proxy-url=<your-proxy-host> --https-proxy-url=<your-proxy-host> --no-proxy=localhost,127.0.0.1,<soar-ip>,192.168.10.0/24

Be warned that configuration change on the apphost wide might affect other functions.


For references:
- https://github.com/ibmresilient/resilient-python-api/blob/main/docs/pages/resilient-lib/resilient-lib.rst
 

Pratik Patil's profile image
Pratik Patil

Hi Alejandro,

no_proxy support is not available in fn_rest_api at the app layer in the current release. It will be supported in an upcoming release.

In the meantime, the following workaround is available.

Workaround — configure proxy bypass at the OS / container level

fn_rest_api uses the RequestsCommon library which, when no proxy is set in app.config, automatically honours the standard OS-level environment variables:

  • HTTP_PROXY / HTTPS_PROXY — routes outbound traffic through the specified proxy
  • NO_PROXY — comma-separated list of hostnames, IPs, or domain suffixes that bypass the proxy entirely

Important prerequisite: This only works if http_proxy and https_proxy are not set in either the [fn_rest_api] or [integrations] sections of app.config. If they are present in app.config, environment variables — including NO_PROXY — are completely ignored.

Once those app.config entries are removed, set the proxy at the OS / container level:

export HTTP_PROXY="http://proxy.corp.com:8080"
export HTTPS_PROXY="http://proxy.corp.com:8080"
export NO_PROXY="internal-host.corp.local,.corp.local,127.0.0.1"
Pattern Effect
internal-api.example.com Bypass a specific hostname
10.0.0.5,192.168.1.0/24 Bypass specific IPs or CIDR ranges
.example.com Bypass all subdomains of a domain
* Bypass everything (effectively disables proxy)


Please find the detailed configuration guide attached.

Regards, IBM SOAR Apps Team