IBM Security QRadar SOAR

 View Only
  • 1.  Automatic AQL search based on artifacts for log sources

    Posted Wed February 05, 2020 04:57 AM
    Hi All,

    Is it possible that during/after escalation automatically run an AQL search based on the incident's artifacts for all log sources for the past week?

    Thank you.

    Regards,
    Adam

    ------------------------------
    Adam
    ------------------------------


  • 2.  RE: Automatic AQL search based on artifacts for log sources

    Posted Wed February 05, 2020 02:30 PM
    Hi Adam,

    In IBM Resilient QRadar Integration Configuration, Preferences tab, you can enable the option:
    "Enable Resilient users to search the Ariel databases from an incident".

    You can use the existing queries or create your own. Then, in an Incident, Artifact tab, you can run
    the "QRadar Ariel Query" Action Rule on the desired artifact.  By default this is a manually-run action.

    Hope this helps!

    AnnMarie

    ------------------------------
    AnnMarie Norcross
    ------------------------------



  • 3.  RE: Automatic AQL search based on artifacts for log sources

    Posted Thu February 06, 2020 02:22 AM
    Hi AnnMarie,

    Yes, I am aware of this option and that is why I asked this question because it is a manual-run action. Is there any way to do it automatically?

    Thank you.

    Adam

    ------------------------------
    Adam
    ------------------------------



  • 4.  RE: Automatic AQL search based on artifacts for log sources

    Posted Thu February 06, 2020 02:59 PM
    Hi Adam,

    If you have the fn_qradar_integration package installed, you can create your own custom automatic rules and use the existing  or create your own custom workflows and functions.  There are examples of querying reference sets for artifact items.

    What do you mean by "log sources"?  Do you mean "reference sets"?

    AnnMarie

    ------------------------------
    AnnMarie Norcross
    ------------------------------



  • 5.  RE: Automatic AQL search based on artifacts for log sources

    Posted Wed February 12, 2020 03:38 AM
    Hi AnnMarie,

    I see.

    I meant Source IPs.

    ------------------------------
    Adam
    ------------------------------