IBM Cloud Pak for Security

Cloud Pak for Security

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Connect qradar to CP4S

    Posted Thu October 21, 2021 01:36 PM
    Hey All,

    I want to be able so send offenses to SOAR. The QRadar connection in CP4S is working.

    I need to configure the
    QRadar SOAR Plugin

    But how do I get the STOMP Parameters?
    - url prefix
    - STOMP Host
    - STOMP Port

    I was guessing and I get the following error:

    QRadar token test failed. 401 Client Error: 401 for url: https://qradarz.cyberlab.systems/api/siem/offense_closing_reasons

    Any ideas?

    ------------------------------
    Maren Sindlinger
    ------------------------------


  • 2.  RE: Connect qradar to CP4S

    Posted Thu October 21, 2021 05:56 PM

    Hi Maren,
    url Prefix:  cases-rest
    stomp port:443

    stomp host can be found in two ways:
    Log in onto the openshift management console, select your cp4s project and look at routes
    or
    log in onto your openshift platform on the command line and use
    oc project << your project name for cp4s >>
    oc get routes

    and make sure the api key you use is created under cp4s >> application settings >> case management >> permissions and access >> users >> tab "API keys"



    ------------------------------
    Good luck,
    Erwin
    ------------------------------