IBM QRadar SOAR

IBM QRadar SOAR

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Alternative way to group similar action to an artifact

    Posted Thu February 02, 2023 09:55 PM
    Edited by Luqman Nur Tue February 07, 2023 03:42 AM
    Hi IBM community,


    I want to ask regarding the implementation of grouping artifacts and doing bulk function with them. I am specifically referring to this feature:
    https://login.ibm.com/oidc/sps/auth?client_id=OGFlMGY3ZDItZGNkOC00&Target=https%3A%2F%2Flogin.ibm.com%2Foidc%2Fendpoint%2Fdefault%2Fauthorize%3FqsId%3D5ecc9163-14f8-4e91-8810-8e85f4ff4f71%26client_id%3DOGFlMGY3ZDItZGNkOC00
    Ibm remove preview
    View this on Ibm >


    Due to the unavailability of this solution, is there any available alternative?

    My current implementation is of the following:
    • The playbook is triggered upon receiving certain artifact types (i.e. Hash value of file)
    • Grab the value of the artifact and artifact type and let user assign label to similar artifact, to tag the artifact for further action needed (i.e. safe or suspicious hash value)
    Issue that I am facing:
    • There is no option to accept user input in the automatic playbook (where the manual one have activation form that can be grab by the function later on)
    My current idea to circumvent the issue:
    • For every tag option that user is available to select (i.e safe or suspicious) , a new playbook is created. So if there is two selection available, there will be two different playbook implemented.
    • For this situation, the user can run automatic playbook for all the artifact that they want to group in one label. So user will turn on the related playbook for one selection run
    Possible problem for my implementation:
    • Complexity issue, it will be very difficult to implement solution to a menu item that requires multiple user input where the option relates which each other
    • Inter-dependency, sometimes it is not possible to separate a selection into a single playbook because a function will related to other
    • Unable to capture unique input from user for example "file name" because playbook can only covers certain use-case.
    I'm sure there are more problem that I could not think of with this implementation but currently this is the best that I could think of. Is there anyone that have come across this issue? , If so how would you manage your unique workflow to overcome this limitation?

    I hope I can get some clarification with this feature, any guidance will be very helpful to my understanding of IBM SOAR as a whole. Thanks for reading

    Best regards,







    ------------------------------
    Luqman Nur
    Techlab
    ------------------------------


  • 2.  RE: Alternative way to group similar action to an artifact

    Posted Sun February 12, 2023 08:10 PM

    Is there any update on this method?



    ------------------------------
    Luqman Nur
    Techlab
    ------------------------------



  • 3.  RE: Alternative way to group similar action to an artifact

    Posted Wed February 15, 2023 07:32 AM
    Edited by Zain Zafar Wed February 15, 2023 10:59 PM

    Hello @Luqman Nur , Thanks



    ------------------------------
    Nouman Ahmad
    ------------------------------



  • 4.  RE: Alternative way to group similar action to an artifact

    Posted Wed February 15, 2023 08:10 PM
    Edited by Luqman Nur Thu February 16, 2023 09:24 PM

    Hi @Nouman, anything you can just contact me through the community portal, since it will be easier for others to chime in and provide additional input



    ------------------------------
    Luqman Nur
    Techlab
    ------------------------------



  • 5.  RE: Alternative way to group similar action to an artifact

    Posted Wed February 15, 2023 11:02 PM

    @Luqman Nur LOL Thank you for telling this xD



    ------------------------------
    Nouman Ahmad
    ------------------------------