IBM Security QRadar SOAR

 View Only
  • 1.  QRadar Ariel Query from Artifact

    Posted Tue November 12, 2019 11:43 AM
    Hello,
    It´s possible get the incident payload by doing an Qradar Ariel Query? The same payload which appears on the Log Activity?
    Thank You.

    ------------------------------
    Aitor Vivanco Sata Cruz
    ------------------------------


  • 2.  RE: QRadar Ariel Query from Artifact

    Posted Tue November 12, 2019 04:02 PM
    Hi Aitor

    I am looking at the QRadar plugin that performs the Ariel search and it prints the results to the log but it also posts the results to the incident as an attachment.  If you go to the Attachment tab of the Incident in Resilient, do you see the same results posted there?

    AnnMarie

    ------------------------------
    AnnMarie Norcross
    ------------------------------



  • 3.  RE: QRadar Ariel Query from Artifact

    Posted Wed November 13, 2019 02:36 AM
    Hi AnnMarie

    It creates a CSV with some details, but instead of that I would like to create the whole payload information on the CSV. I mean, extract the same log text that appears on the Log Activity > Event

    Thank you.
     





  • 4.  RE: QRadar Ariel Query from Artifact

    IBM Champion
    Posted Thu November 14, 2019 09:58 AM
    You must modify the AQL you are using to include the payload within the results.

    SELELECT UTF8(payload)


    See more on AQL fields here:
    https://www.ibm.com/support/knowledgecenter/SS42VS_7.3.1/com.ibm.qradar.doc/c_aql_even_flow_fields_ref.html

    ------------------------------
    Jared Fagel
    Cyber Security Analyst Intern
    Public Utility
    ------------------------------



  • 5.  RE: QRadar Ariel Query from Artifact

    Posted Mon November 18, 2019 03:44 AM
    Hello Jared,

    It works! Thank you for the help too.

    ------------------------------
    Aitor Vivanco Sata Cruz
    ------------------------------