IBM QRadar SOAR

IBM QRadar SOAR

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  parse csv attachment on the apphost

    Posted 8 days ago

    hello,

    is there an elegant way to transfer the email attachment of an incoming email to the apphost for further processing?

    my first thought is to add it as incident attachment, then using a rule + workflow to trigger a function on the apphost (transmit the incident id and then get the attachment via qradar's api)

    is there a better solution? can the file be pushed to the apphost instead of being pulled by it, like described above?

    many thanks for any hint which could point me to the right direction of further researching this issue 



    ------------------------------
    petre b
    ------------------------------


  • 2.  RE: parse csv attachment on the apphost

    Posted 8 days ago

    Hi ,

    I didn't understand your requirement, why you need email attachment file in App host?
    Can you give more words .

    Thanks,

    Sai



    ------------------------------
    Sai Kumar Reddy Dhubbaka
    ------------------------------



  • 3.  RE: parse csv attachment on the apphost

    Posted 7 days ago

    hi,

    I want to extract some strings from the csv file and add them as artifacts; with the limited python libraries in qradar it is quite difficult, that's why I thought transferring the file to the apphost would be the best solution, as there one can install any library required (e.g. parse the csv as pandas dataframe)

    thanks,

    petre



    ------------------------------
    petre b
    ------------------------------



  • 4.  RE: parse csv attachment on the apphost

    Posted 5 days ago

    for that I use the function Utilities: Excel Query from the app Utility Functions for SOAR to read excel files ,the app is decommissioned though so you need to ask support for an old version of it.



    ------------------------------
    Mohamad islam Hamadieh
    I post SOAR content and tips on linkedIn , follow me :)
    https://linkedin.com/in/mohamadislam
    ------------------------------



  • 5.  RE: parse csv attachment on the apphost

    Posted 2 days ago

    Hi,

    could you please download this function and use the function base64 to attachment function to create a file and attach to incident .
    IBM Application Exchange - SOAR Function Utilities for SOAR

    Thanks,

    Sai



    ------------------------------
    Sai Kumar Reddy Dhubbaka
    ------------------------------