Linsong,
understand. Good idea to integrate TOR IPs.
Basically QRadar supports two methods.
One is ReferenceDataUtil.sh CLI tool you can use to update your refdata. learning academy hast 3 courses available covering refsets.
The other method is Rest API where you have many commands available to enhance your ref data.
if you want to create your TOR list you call
curl -s -X POST -u admin -H 'Version: 12.0' -H 'Accept: application/json' 'https://192.168.1.80/api/reference_data/sets?element_type=ALN&name=TOR%20black%20list'
afterwards you can bulk load or indivdually load IPs into it
BR Karl
------------------------------
[Karl] [Jaeger] [Business Partner]
[QRadar Specialist]
[pro4bizz]
[Karlsruhe] [Germany]
[4972190981722]
------------------------------
Original Message:
Sent: Fri February 19, 2021 12:17 AM
From: Linsong Guo
Subject: Reference set auto update
Hi Ka
I am looking form monitoring TOR exit node IP which means the reference set will contain a list of TOR exit node IP.
I am thing about curl the list from TOR website and get imported into the reference set but not sure how to get the data into Qradar
Cheers
L
Original Message:
Sent: 2/16/2021 9:55:00 AM
From: Karl Jaeger
Subject: RE: Reference set auto update
Linsong,
you are probably aware of how to update your custom reference data using the rule wizard.
My guess is what you are really looking for is an external data feeds, e.g. STIX or TAXII.
Pls refer to https://community.ibm.com/community/user/security/communities/community-home/digestviewer/viewthread?MessageKey=c7636b7d-b44a-4594-ad7a-07f746dffc67&CommunityKey=f9ea5420-0984-4345-ba7a-d93b4e2d4864&tab=digestviewer#bmc7636b7d-b44a-4594-ad7a-07f746dffc67
BR
Ka
------------------------------
[Karl] [Jaeger] [Business Partner]
[QRadar Specialist]
[pro4bizz]
[Karlsruhe] [Germany]
[4972190981722]
Original Message:
Sent: Mon February 15, 2021 06:29 PM
From: Linsong Guo
Subject: Reference set auto update
HI Everyone,
I want to auto update a reference set which contain a IP list I want to monitoring, anyone has any documentation on how to do this?
Thank you for your help
Regards
------------------------------
Linsong Guo
------------------------------