QRadar XDR

  • 1.  Auto assign offense

    Posted 10 days ago
    Hello,

    Is there a way to auto assign offenses to an analyst based on the offense type or rule that triggered the offense?

    ------------------------------
    Josh
    ------------------------------


  • 2.  RE: Auto assign offense

    Posted 10 days ago
    Hi Josh,

    with the help of the qradar api and for example a python script you should be able to implement your requirements.
    The attributes for offense_type and assigned_to are available to you there. Hope that helps you first.
    Further information can be found in the API documentation in the section /siem/offenses /{offense_id}

    Regards,
    Ralph

    ------------------------------
    Ralph Belfiore
    SIEM Expert
    pro4bizz GmbH
    Karlsruhe
    +4972190981727
    ------------------------------



  • 3.  RE: Auto assign offense

    Posted 9 days ago
    Hello @Josh V ,

    You can do this on your own as specified by Ralph.

    There is also an alternative with an app that do the job from the company ScienceSoft : QIN (QRadar Incident Notifier).

    https://exchange.xforce.ibmcloud.com/hub/extension/7fcc709a5d2aa4eec6daca7192d8253c

    Regards,
    Zoldax


    ------------------------------
    @zoldax

    https://www.youracclaim.com/users/pascal-weber.029e134d/badges
    ------------------------------