Hello Raymond,
as you have already noticed, only these 4 fields are supported.
maintaining asset information is a bit more complex. But the context information you mentioned can be wonderfully maintained and updated via the API.
Depending on the skill, the API can be addressed via python or alternatively with powershell. In order to update an asset with additional context, the respective asset id is addressed and the corresponding fields and values are transferred.
Perhaps the following video by Jose Bravo on the subject of 'qradar api 101' will help you.
https://www.youtube.com/watch?v=swGI5QWB29gBest Regards,
Ralph
------------------------------
Ralph Belfiore
SIEM Expert
pro4bizz GmbH
Karlsruhe
+4972190981727
------------------------------
Original Message:
Sent: Fri October 15, 2021 07:47 PM
From: Raymond Tam
Subject: Import Asset from CSV using python script via API
I am looking for a way to import Assets into QRadar regularly. The existing CSV import from the WebUI only support 4 fields IP, name, weight, description.
I found a very old script on Github that can import other field via API but I can't get it to work since it is based on Python 2. Do you have a more updated script that can do the similar function? I am looking for a way to import asset information with the Owner, Technical Contact and custom field.
data-import/assets at master · ibm-security-intelligence/data-importGitHub | remove preview |
| data-import/assets at master · ibm-security-intelligence/data-import | A simple utility to load a CSV file with asset information into the QRadar asset model based on IP address (which must exist in QRadar). The first column of the first line of the file must be 'ipaddress'. The remaining columns of the file must contain field name headers that match the asset properties being loaded. | View this on GitHub > |
|
|
------------------------------
Raymond Tam
------------------------------