IBM Security QRadar

 View Only
  • 1.  Integrating Darktrace with Qradar

    Posted Mon July 15, 2019 03:52 PM
    Hi
    Has someone integrated Darktrace with Qradar? 
    I readed in the products page of Darktrace that it can be integrated to Qradar throught a connector in the LEEF format but i don't find any information about how to do it.
    Thanks.

    ------------------------------
    Johan López
    ------------------------------


  • 2.  RE: Integrating Darktrace with Qradar

    Posted Tue July 16, 2019 10:48 AM
    Edited by Ian Lewis Wed July 17, 2019 10:32 AM
    It is very easy to do so, but it is only for DarkTrace "alerts". Just need to tell DT about the syslog server and format. They don't share their admin guides, you need to download them from the support portal. 



  • 3.  RE: Integrating Darktrace with Qradar

    Posted Thu August 08, 2019 05:00 AM
    Hi, Can confirm same as what Ian said below as we had to do the same process for a customer. Download all the info from the support portal.

    ------------------------------
    Adam Jones
    ------------------------------