Hi Aitor,
In QRadar you can get raw payloads like this:
select utf8(payload) from events last 5 minutes
You can create this query on Resilient App, can create a script to get logs from QRadar API etc. I hope this helps.
------------------------------
Burak Karaca
------------------------------
Original Message:
Sent: Tue November 12, 2019 04:35 AM
From: Aitor Vivanco Sata Cruz
Subject: QRadar Ariel Query to the Artifact
Hello,
It is possible to get the event payloads by doing Qradar Ariel Query to the Artifact. The same payload which appears on the log event.
------------------------------
Aitor Vivanco Sata Cruz
------------------------------