Ibm Qradar
IBM QRadar is a leading SIEM platform that provides real-time threat detection and security intelligence.
IBM QRadar is a comprehensive security information and event management (SIEM) platform that provides real-time visibility and analysis of security data. The IBM QRadar connector for Swimlane Turbine allows users to automate SIEM operations, enhance threat detection, and streamline incident response. By integrating with IBM QRadar, Swimlane Turbine users can efficiently manage offenses, perform advanced searches, and maintain reference data, thereby improving security posture and operational efficiency.
Prerequisites
Before you can use the IBM QRadar connector for Turbine, you'll need access to the IBM QRadar API. This requires the following:
- an API key authentication using the following parameters:
- URL: The endpoint URL for accessing the IBM QRadar API.
- API Key: A unique key provided by IBM QRadar for authenticating API requests.
Asset Setup
If you want to use a specific version of API, please use the API Version parameter in the asset. By default, the API uses the latest version.
Capabilities
The IBM QRadar integration provides the following capabilities:
- Add/Update Data in Reference Map
- Add/Update Data in Reference Table
- Create Reference Map of Sets
- Create Reference Map
- Create Reference Table
- Get Offense Saved Search
- Get Reference Map of Sets
- List Assets
- List Reference Maps
- List Reference Tables
- List Rules
- Get Local Destination Address
- Get Log Source Types
- Create Log Source
- Get Log Sources ... and so on
Get Offenses and Events
Fetches QRadar offenses, retrieves associated events via AQL searches, parses IOCs, and returns enriched TEDS-format alerts.
Endpoints used:
Method | Endpoint | Purpose |
|---|---|---|
GET | /api/siem/offenses | Retrieve offenses with optional filter, sort, and fields |
POST | /api/ariel/searches | Submit AQL search for each offense's events |
GET | /api/ariel/searches/{search_id} | Poll search status until COMPLETED, ERROR, or CANCELLED |
GET | /api/ariel/searches/{search_id}/results | Fetch up to 100 events for a completed search |
DELETE | /api/ariel/searches/{search_id} | Clean up search after results are retrieved or on timeout |
Notes
- For more information on Ariel Query Language (AQL), see IBM AQL.
Additional Documentation
Configurations
IBM QRadar API Key Authentication
Authenticates using an API Key
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
SEC | API key | string | Required |
api_version | API Version | string | Optional |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Add/Update Data in Reference Map
Add or update data in a specific IBM QRadar reference map using the provided map name and data.
Endpoint
- URL: /api/reference_data/maps/bulk_load/{{name}}
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.name | string | Required | Parameters for the Add/Update Data in Reference Map action |
parameters.fields | string | Optional | Parameters for the Add/Update Data in Reference Map action |
data | array | Optional | Response data |
Input Example
{"path_parameters":{"name":"Example Name"},"parameters":{"fields":"string"},"data":[]}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
creation_time | number | Time value |
element_type | string | Type of the resource |
name | string | Name of the resource |
number_of_elements | number | Output field: number_of_elements |
time_to_live | string | Output field: time_to_live |
timeout_type | string | Type of the resource |
Output Example
{"status_code":201,"response_headers":{},"reason":"CREATED","json_body":{"creation_time":42,"element_type":"String <one of: ALN, NUM, IP, PORT, ALNIC, DATE>","name":"String","number_of_elements":42,"time_to_live":"String","timeout_type":"String <one of: UNKNOWN, FIRST_SEEN, LAST_SEEN>"}}
Add/Update Data in Reference Table
Add or update data in a specified IBM QRadar reference table using the 'name' identifier and provided 'data'.
Endpoint
- URL: /api/reference_data/tables/bulk_load/{{name}}
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.name | string | Required | Parameters for the Add/Update Data in Reference Table action |
parameters.fields | string | Optional | Parameters for the Add/Update Data in Reference Table action |
data | array | Optional | Response data |
Input Example
{"path_parameters":{"name":"Example Name"},"parameters":{"fields":"string"},"data":[]}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
creation_time | number | Time value |
element_type | string | Type of the resource |
name | string | Name of the resource |
number_of_elements | number | Output field: number_of_elements |
time_to_live | string | Output field: time_to_live |
timeout_type | string | Type of the resource |
Output Example
{"status_code":201,"response_headers":{},"reason":"CREATED","json_body":{"creation_time":42,"element_type":"String <one of: ALN, NUM, IP, PORT, ALNIC, DATE>","name":"String","number_of_elements":42,"time_to_live":"String","timeout_type":"String <one of: UNKNOWN, FIRST_SEEN, LAST_SEEN>"}}
Collect Events and Build Alerts
Collects AQL search results for QRadar offenses, parses IOC observables, and builds structured alert objects ready for ingestion.
Endpoint
- URL: api/ariel/searches
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.offenses | array | Optional | Array of QRadar offense objects from get_offenses_and_submit_searches. |
parameters.search_ids | array | Optional | Array of {offense_id, search_id} pairs from get_offenses_and_submit_searches. |
parameters.search_ids.offense_id | number | Optional | Parameters for the Collect Events and Build Alerts action |
parameters.search_ids.search_id | string | Optional | Parameters for the Collect Events and Build Alerts action |
parameters.fetch_user_emails | boolean | Optional | When true, calls GET /api/config/access/users to resolve the email for the username in each offense's assigned_to field. |
parameters.ioc_types | string | Optional | Comma-separated list of IOC types to extract. Defaults to all types when omitted. |
parameters.domains_ignore_list | string | Optional | Comma-separated list of domains to exclude from observable extraction. |
parameters.ip_cidr_ignore_list | string | Optional | Comma-separated list of CIDR ranges to exclude from observable extraction. |
parameters.regex_ignore | string | Optional | Regex pattern. Observables matching this pattern are excluded from extraction. |
parameters.ioc_ignore_paths | array | Optional | Array of slash-separated field paths in event objects to exclude before IOC parsing. Supports wildcards. |
Input Example
{"parameters":{"offenses":[],"search_ids":[{"offense_id":123,"search_id":"string"}],"fetch_user_emails":true,"ioc_types":"string","domains_ignore_list":"string","ip_cidr_ignore_list":"string","regex_ignore":"string","ioc_ignore_paths":["string"]}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
Alerts | array | Array of structured alert objects built from QRadar offenses and their AQL event results. |
Alerts.alert_uid | string | Unique identifier |
Alerts.alert_title | string | Output field: Alerts.alert_title |
Alerts.alert_description | string | Output field: Alerts.alert_description |
Alerts.alert_severity | string | Output field: Alerts.alert_severity |
Alerts.alert_categories | array | Output field: Alerts.alert_categories |
Alerts.alert_provider | string | Unique identifier |
Alerts.alert_created_timestamp | string | Output field: Alerts.alert_created_timestamp |
Alerts.alert_updated_timestamp | string | Output field: Alerts.alert_updated_timestamp |
Alerts.alert_end_timestamp | string | Output field: Alerts.alert_end_timestamp |
Alerts.alert_ingested_timestamp | string | Output field: Alerts.alert_ingested_timestamp |
Alerts.is_new_alert | boolean | Output field: Alerts.is_new_alert |
Alerts.alert_rules | array | Output field: Alerts.alert_rules |
Alerts.alert_impacted_ip_addresses | array | Output field: Alerts.alert_impacted_ip_addresses |
Alerts.alert_impacted_usernames | array | Name of the resource |
Alerts.alert_impacted_hostnames | array | Name of the resource |
Alerts.assigned_to | string | Username the offense is assigned to in QRadar. |
Alerts.assigned_to_email | string | Email of the assigned_to user, resolved via GET /api/config/access/users. Empty string when fetch_user_emails is false or user has no email. |
Alerts.observables | array | IOC observables extracted from event data. |
Alerts.observables.observable_type | string | Type of the resource |
Alerts.observables.observable_value | string | Value for the parameter |
Alerts.raw_alert | array | Output field: Alerts.raw_alert |
total_processed | number | Number of offenses processed in this invocation. |
latest_updated_timestamp | number | Epoch ms of the most recently updated offense in this batch. |
Output Example
{"Alerts":[{"alert_uid":"string","alert_title":"string","alert_description":"string","alert_severity":"string","alert_categories":[],"alert_provider":"string","alert_created_timestamp":"string","alert_updated_timestamp":"string","alert_end_timestamp":"string","alert_ingested_timestamp":"string","is_new_alert":true,"alert_rules":[],"alert_impacted_ip_addresses":[],"alert_impacted_usernames":[],"alert_impacted_hostnames":[]}],"total_processed":123,"latest_updated_timestamp":123,"pending_count":123...
Create Reference Map
Initiate the creation of a new reference map in IBM QRadar using the provided 'name' parameter.
Endpoint
- URL: /api/reference_data/maps
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.name | string | Required | Parameters for the Create Reference Map action |
parameters.key_label | string | Optional | Parameters for the Create Reference Map action |
parameters.value_label | string | Optional | Parameters for the Create Reference Map action |
parameters.element_type | string | Optional | Parameters for the Create Reference Map action |
parameters.timeout_type | string | Optional | Parameters for the Create Reference Map action |
parameters.time_to_live | string | Optional | Parameters for the Create Reference Map action |
parameters.fields | string | Optional | Parameters for the Create Reference Map action |
Input Example
{"parameters":{"name":"Example Name","key_label":"string","value_label":"string","element_type":"string","timeout_type":"string","time_to_live":"string","fields":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
collection_id | number | Unique identifier |
creation_time | number | Time value |
element_type | string | Type of the resource |
key_label | string | Output field: key_label |
name | string | Name of the resource |
namespace | string | Name of the resource |
number_of_elements | number | Output field: number_of_elements |
time_to_live | string | Output field: time_to_live |
timeout_type | string | Type of the resource |
value_label | string | Value for the parameter |
Output Example
{"status_code":201,"response_headers":{},"reason":"CREATED","json_body":{"collection_id":42,"creation_time":42,"element_type":"String <one of: ALN, NUM, IP, PORT, ALNIC, DATE>","key_label":"String","name":"String","namespace":"String <one of: PRIVATE, SHARED, TENANT>","number_of_elements":42,"time_to_live":"String","timeout_type":"String <one of: UNKNOWN, FIRST_SEEN, LAST_SEEN>","value_label":"String"}}
Create Reference Map of Sets
Create a new reference map of sets in IBM QRadar, requiring a specified name and element type for setup.
Endpoint
- URL: api/reference_data/map_of_sets
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.name | string | Required | The name of the reference map of sets to create. |
parameters.element_type | string | Required | The element type for the values allowed in the reference map of sets. |
parameters.key_label | string | Optional | The label to describe the keys. |
parameters.value_label | string | Optional | The label to describe the data values. |
parameters.timeout_type | string | Optional | This indicates if the time_to_live interval is based on when the data was first seen or last seen. |
parameters.time_to_live | string | Optional | The time to live interval. |
parameters.fields | string | Optional | Use this parameter to specify which fields you would like to get back in the response. |
Input Example
{"parameters":{"name":"Example Name","element_type":"string","key_label":"string","value_label":"string","timeout_type":"string","time_to_live":"string","fields":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
creation_time | number | Time value |
element_type | string | Type of the resource |
key_label | string | Output field: key_label |
name | string | Name of the resource |
number_of_elements | number | Output field: number_of_elements |
time_to_live | string | Output field: time_to_live |
timeout_type | string | Type of the resource |
value_label | string | Value for the parameter |
Output Example
{"status_code":201,"response_headers":{},"reason":"OK","json_body":{"creation_time":42,"element_type":"ALN","key_label":"String","name":"String","number_of_elements":42,"time_to_live":"String","timeout_type":"FIRST_SEEN","value_label":"String"}}
Create Reference Table
Create a new reference table in IBM QRadar with a specified name and element type.
Endpoint
- URL: /api/reference_data/tables
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.name | string | Required | Parameters for the Create Reference Table action |
parameters.outer_key_label | string | Optional | Parameters for the Create Reference Table action |
parameters.key_name_types | string | Optional | Parameters for the Create Reference Table action |
parameters.element_type | string | Required | Parameters for the Create Reference Table action |
parameters.timeout_type | string | Optional | Parameters for the Create Reference Table action |
parameters.time_to_live | string | Optional | Parameters for the Create Reference Table action |
parameters.fields | string | Optional | Parameters for the Create Reference Table action |
Input Example
{"parameters":{"name":"Example Name","outer_key_label":"string","key_name_types":"Example Name","element_type":"string","timeout_type":"string","time_to_live":"string","fields":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
collection_id | number | Unique identifier |
creation_time | number | Time value |
element_type | string | Type of the resource |
key_label | string | Output field: key_label |
key_name_types | object | Name of the resource |
key_name_types.String | string | Name of the resource |
name | string | Name of the resource |
namespace | string | Name of the resource |
number_of_elements | number | Output field: number_of_elements |
time_to_live | string | Output field: time_to_live |
timeout_type | string | Type of the resource |
Output Example
{"status_code":201,"response_headers":{},"reason":"CREATED","json_body":{"collection_id":42,"creation_time":42,"element_type":"String <one of: ALN, NUM, IP, PORT, ALNIC, DATE>","key_label":"String","key_name_types":{"String":"String <one of: ALN, NUM, IP, PORT, ALNIC, DATE>"},"name":"String","namespace":"String <one of: PRIVATE, SHARED, TENANT>","number_of_elements":42,"time_to_live":"String","timeout_type":"String <one of: UNKNOWN, FIRST_SEEN, LAST_SEEN>"}}
Get Custom Properties
Retrieves a list of event regex custom properties defined in IBM QRadar, including property name, type, and whether it is used by the rule engine.
Endpoint
- URL: api/config/event_sources/custom_properties/regex_properties
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
headers | object | Optional | HTTP headers for the request |
headers.Range | string | Optional | Restricts the number of custom properties returned. Follows QRadar Range header format. |
parameters.filter | string | Optional | Optional QRadar filter expression to restrict the list of custom properties returned. Example: property_type = 'string' |
parameters.fields | string | Optional | Optional comma-separated list of fields to include in the response (IBM field projection syntax). If omitted, all fields are returned. |
Input Example
{"headers":{"Range":"string"},"parameters":{"filter":"string","fields":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
custom_properties | array | List of event regex custom property objects from GET /api/config/event_sources/custom_properties/regex_properties. Each object includes id, identifier, name, property_type, use_for_rule_engine, description, username, datetime_format, locale, and auto_discovered. |
custom_properties.id | number | Unique identifier |
custom_properties.identifier | string | Unique identifier |
custom_properties.name | string | The field name to use in AQL SELECT clause. |
custom_properties.property_type | string | One of string, numeric, ip, port, time. |
custom_properties.use_for_rule_engine | boolean | True if parsed at ingest time (indexed). |
custom_properties.description | string | Output field: custom_properties.description |
custom_properties.username | string | Name of the resource |
custom_properties.datetime_format | string | Output field: custom_properties.datetime_format |
custom_properties.locale | string | Output field: custom_properties.locale |
custom_properties.auto_discovered | boolean | Output field: custom_properties.auto_discovered |
Output Example
{"custom_properties":[{"id":123,"identifier":"string","name":"Example Name","property_type":"string","use_for_rule_engine":true,"description":"string","username":"Example Name","datetime_format":"string","locale":"string","auto_discovered":true}]}
Get Deployed Users
Retrieves a list of all deployed users from QRadar via GET /api/config/access/users. Returns all users when called with ADMIN capability, users without ADMIN when called with SAASADMIN, or only the current user otherwise.
Endpoint
- URL: api/config/access/users
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
headers | object | Optional | HTTP headers for the request |
headers.Range | string | Optional | Restricts the number of users returned. Follows QRadar Range header format (e.g. items=0-49). |
parameters.current_user | boolean | Optional | When true, only returns the caller's user. If called with an authorized service, no user will be returned. |
parameters.filter | string | Optional | Optional. Restricts the elements in the list based on the contents of various fields. |
parameters.sort | string | Optional | Optional. Used to sort the elements in the list. |
parameters.fields | string | Optional | Optional. Comma-separated list of fields to include in the response. Fields not named are excluded. |
parameters.page_number | number | Optional | 1-based page number to fetch. Use with page_size for Turbine loop pagination. Takes priority over the Range header. If omitted, Range header behaviour applies. |
ο»Ώ | |||
parameters.page_size | number | Optional | Number of users per page when using page_number. Defaults to 50 if not set. |
Input Example
{"headers":{"Range":"string"},"parameters":{"current_user":true,"filter":"string","sort":"string","fields":"string","page_number":123,"page_size":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
users | array | Array of deployed user objects from GET /api/config/access/users. |
users.id | number | Unique identifier |
users.username | string | Name of the resource |
users.email | string | Output field: users.email |
users.description | string | Output field: users.description |
users.user_role_id | number | Unique identifier |
users.security_profile_id | number | Unique identifier |
users.locale_id | string | Unique identifier |
users.enable_popup_notifications | boolean | Output field: users.enable_popup_notifications |
users.old_password | string | Output field: users.old_password |
users.password | string | Output field: users.password |
users.password_creation_time | number | Time value |
users.tenant_id | number | Unique identifier |
users.allow_system_authentication_fallback | boolean | Output field: users.allow_system_authentication_fallback |
users.local_only_account | boolean | Count value |
users.inactivity_timeout | number | Output field: users.inactivity_timeout |
users.notification_flag | string | Output field: users.notification_flag |
users.show_awf_default_dashboard | string | Output field: users.show_awf_default_dashboard |
users.display_theme | string | Output field: users.display_theme |
total_users_fetched | number | Output field: total_users_fetched |
total_users_available | number | Total users matching the filter (from Content-Range header). |
page_number | number | Output field: page_number |
page_size | number | Output field: page_size |
total_pages | number | Output field: total_pages |
Output Example
{"users":[{"id":123,"username":"Example Name","email":"[email protected]","description":"string","user_role_id":123,"security_profile_id":123,"locale_id":"string","enable_popup_notifications":true,"old_password":"string","password":"string","password_creation_time":123,"tenant_id":123,"allow_system_authentication_fallback":true,"local_only_account":true,"inactivity_timeout":123}],"total_users_fetched":123,"total_users_available":123,"page_number":123,"page_size":123,"total_pages":123,"has_more":t...
Get Offense Saved Search
Retrieve a specific saved search for offenses in IBM QRadar using the provided search ID.
Endpoint
- URL: api/siem/offense_saved_searches/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | number | Required | Parameters for the Get Offense Saved Search action |
headers | object | Optional | HTTP headers for the request |
headers.Range | string | Optional | Use this parameter to restrict the number of elements that are returned in the list to a specified range. |
parameters.filter | string | Optional | This parameter is used to restrict the elements in a list base on the contents of various fields. |
parameters.fields | string | Optional | Use this parameter to specify which fields you would like to get back in the response. |
Input Example
{"path_parameters":{"id":1}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | number | Unique identifier |
name | string | Name of the resource |
owner | string | Output field: owner |
Output Example
{"status_code":201,"response_headers":{},"reason":"OK","json_body":{"id":42,"name":"String","owner":"String"}}
Get Offenses and Submit Searches
Fetch IBM QRadar offenses and submit AQL event searches, returning offenses with optional notes and search IDs for event collection and alert building.
Endpoint
- URL: api/siem/offenses
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
headers | object | Optional | HTTP headers for the request |
headers.Range | string | Optional | Restricts the number of offenses returned. Follows QRadar Range header format. |
parameters.page_number | number | Optional | 1-based page number to fetch. Use with page_size for Turbine loop pagination. Takes priority over the Range header. If omitted, Range header behaviour applies. |
ο»Ώ | |||
parameters.page_size | number | Optional | Number of offenses per page when using page_number. Defaults to 50 if not set. |
ο»Ώ | |||
parameters.filter | string | Optional | QRadar filter expression applied to the offenses query. If omitted, all offenses within the specified range are returned. |
ο»Ώ | |||
parameters.sort | string | Optional | Field to sort the offenses by. |
parameters.fields | string | Optional | Optional. Comma-separated list forwarded to IBM QRadar GET /api/siem/offenses as the fields query parameter (IBM field projection syntax). If omitted, QRadar returns full offense objects with all default fields. |
ο»Ώ | |||
parameters.include_notes | boolean | Optional | When true, fetches notes for each offense and attaches them as offense.notes (array of note objects: note_text, create_time, id, username). Fetches run in parallel. |
ο»Ώ | |||
parameters.custom_fields | boolean | Optional | When true, queries QRadar for custom field definitions and their log-source-type mappings, then appends the relevant custom field names to the AQL SELECT clause for each offense based on its log source types. Custom fields are not returned by SELECT * alone. Adds two API calls per invocation (fetched once, not per offense). |
ο»Ώ |
Input Example
{"headers":{"Range":"string"},"parameters":{"page_number":123,"page_size":123,"filter":"string","sort":"string","fields":"string","include_notes":true,"custom_fields":true}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
offenses | array | QRadar offense objects from GET /api/siem/offenses; full fields when parameters.fields omitted. Includes id, description, assigned_to, categories, severity, status, rules, log_sources, counts, networks, timestamps. include_notes adds notes[]. |
search_ids | array | Array of {offense_id, search_id} pairs for submitted AQL searches. |
search_ids.offense_id | number | Unique identifier |
search_ids.search_id | string | Unique identifier |
total_offenses_fetched | number | Number of offenses fetched in this call. |
total_offenses_available | number | Total offenses in QRadar matching the filter (from Content-Range header). |
page_number | number | Output field: page_number |
page_size | number | Output field: page_size |
total_pages | number | Output field: total_pages |
has_more | boolean | True if there are more pages to fetch. Use as Turbine loop condition. |
message | string | Set to "no data in array" when no offenses are returned. |
Output Example
{"offenses":[],"search_ids":[{"offense_id":123,"search_id":"string"}],"total_offenses_fetched":123,"total_offenses_available":123,"page_number":123,"page_size":123,"total_pages":123,"has_more":true,"message":"string"}
Get Reference Map of Sets
Retrieve a comprehensive list of all reference map sets available in IBM QRadar.
Endpoint
- URL: api/reference_data/map_of_sets
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
headers | object | Optional | HTTP headers for the request |
headers.Range | string | Optional | Use this parameter to restrict the number of elements that are returned in the list to a specified range. |
parameters.filter | string | Optional | This parameter is used to restrict the elements in a list base on the contents of various fields. |
parameters.fields | string | Optional | Use this parameter to specify which fields you would like to get back in the response. |
Input Example
{"headers":{"Range":"string"},"parameters":{"filter":"string","fields":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
creation_time | number | Time value |
element_type | string | Type of the resource |
key_label | string | Output field: key_label |
name | string | Name of the resource |
number_of_elements | number | Output field: number_of_elements |
time_to_live | string | Output field: time_to_live |
timeout_type | string | Type of the resource |
value_label | string | Value for the parameter |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"creation_time":42,"element_type":"String <one of: ALN, NUM, IP, PORT, ALNIC, DATE>","key_label":"String","name":"String","number_of_elements":42,"time_to_live":"String","timeout_type":"String <one of: UNKNOWN, FIRST_SEEN, LAST_SEEN>","value_label":"String"}}
List Assets
Retrieve a comprehensive overview of all network elements from the IBM QRadar asset model.
Endpoint
- URL: api/asset_model/assets
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.filter | string | Optional | This parameter is used to restrict the elements in a list base on the contents of various fields. |
parameters.fields | string | Optional | Use this parameter to specify which fields you would like to get back in the response. Fields that are not named are excluded. Specify subfields in brackets and multiple fields in the same object are separated by commas. |
parameters.sort | string | Optional | This parameter is used to sort the elements in a list. |
headers | object | Optional | HTTP headers for the request |
headers.range | string | Optional | Use this parameter to restrict the number of elements that are returned in the list to a specified range. The list is indexed starting at zero. |
Input Example
{"parameters":{"filter":"string","fields":"string","sort":"string"},"headers":{"range":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":[{"vulnerability_count":42,"interfaces":[],"risk_score_sum":42.5,"hostnames":[],"id":42,"domain_id":42,"properties":[],"users":[],"products":[]}]}
List Reference Maps
Retrieve all available reference maps from IBM QRadar to enhance context and decision-making.
Endpoint
- URL: /api/reference_data/maps
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.filter | string | Optional | Parameters for the List Reference Maps action |
parameters.fields | string | Optional | Parameters for the List Reference Maps action |
headers | object | Optional | HTTP headers for the request |
headers.Range | string | Optional | HTTP headers for the request |
Input Example
{"parameters":{"filter":"string","fields":"string"},"headers":{"Range":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":[{"collection_id":42,"creation_time":42,"element_type":"String <one of: ALN, NUM, IP, PORT, ALNIC, DATE>","key_label":"String","name":"String","namespace":"String <one of: PRIVATE, SHARED, TENANT>","number_of_elements":42,"time_to_live":"String","timeout_type":"String <one of: UNKNOWN, FIRST_SEEN, LAST_SEEN>","value_label":"String"}]}
List Reference Tables
Retrieve all available reference tables from IBM QRadar to enhance query and analysis capabilities.
Endpoint
- URL: /api/reference_data/tables
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.filter | string | Optional | Parameters for the List Reference Tables action |
parameters.fields | string | Optional | Parameters for the List Reference Tables action |
headers | object | Optional | HTTP headers for the request |
headers.Range | string | Optional | HTTP headers for the request |
Input Example
{"parameters":{"filter":"string","fields":"string"},"headers":{"Range":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":[{"collection_id":42,"creation_time":42,"element_type":"String <one of: ALN, NUM, IP, PORT, ALNIC, DATE>","key_label":"String","key_name_types":{},"name":"String","namespace":"String <one of: PRIVATE, SHARED, TENANT>","number_of_elements":42,"time_to_live":"String","timeout_type":"String <one of: UNKNOWN, FIRST_SEEN, LAST_SEEN>"}]}
List Rules
Retrieve a comprehensive list of rules from IBM QRadar for analysis or modification.
Endpoint
- URL: /api/analytics/rules
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.filter | string | Optional | Parameters for the List Rules action |
parameters.fields | string | Optional | Parameters for the List Rules action |
headers | object | Optional | HTTP headers for the request |
headers.Range | string | Optional | HTTP headers for the request |
Input Example
{"parameters":{"filter":"string","fields":"string"},"headers":{"Range":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":[{"average_capacity":42,"base_capacity":42,"base_host_id":42,"capacity_timestamp":42,"creation_date":42,"enabled":true,"id":42,"identifier":"String","linked_rule_identifier":"String","modification_date":42,"name":"String","origin":"String <one of: SYSTEM, OVERRIDE, USER>","owner":"String","type":"String <one of: EVENT, FLOW, COMMON, OFFENSE>"}]}
Get Local Destination Address
Retrieve a specific local destination address in IBM QRadar using the provided address ID.
Endpoint
- URL: api/siem/local_destination_addresses/{{local_destination_address_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.local_destination_address_id | string | Required | Parameters for the Get Local Destination Address action |
parameters.fields | string | Optional | Parameters for the Get Local Destination Address action |
Input Example
{"parameters":{"fields":"field_one (field_two, field_three),field_four"},"path_parameters":{"local_destination_address_id":"2"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
event_flow_count | number | Count value |
source_address_ids | array | Unique identifier |
first_event_flow_seen | number | Output field: first_event_flow_seen |
last_event_flow_seen | number | Output field: last_event_flow_seen |
magnitude | number | Output field: magnitude |
id | number | Unique identifier |
offense_ids | array | Unique identifier |
local_destination_ip | string | Output field: local_destination_ip |
domain_id | number | Unique identifier |
network | string | Output field: network |
Output Example
{"event_flow_count":123,"source_address_ids":[123],"first_event_flow_seen":123,"last_event_flow_seen":123,"magnitude":123,"id":123,"offense_ids":[123],"local_destination_ip":"string","domain_id":123,"network":"string"}
Get Log Source Types
Retrieve a comprehensive list of log source types from IBM QRadar for improved data categorization and analysis.
Endpoint
- URL: api/config/event_sources/log_source_management/log_source_types
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.fields | string | Optional | Parameters for the Get Log Source Types action |
parameters.filter | string | Optional | Parameters for the Get Log Source Types action |
headers | object | Optional | HTTP headers for the request |
headers.range | string | Optional | HTTP headers for the request |
Input Example
{"parameters":{"fields":"field_one (field_two, field_three),field_four","filter":"log_source_extension_id = '0'"},"headers":{"range":"items=0-49"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
[]
Create Log Source
Create a new log source in IBM QRadar using the provided configuration details.
Endpoint
- URL: api/config/event_sources/log_source_management/log_sources
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parsing_order | number | Optional | Parameter for Create Log Source |
internal | boolean | Optional | Parameter for Create Log Source |
gateway | boolean | Optional | Parameter for Create Log Source |
protocol_parameters | array | Optional | Parameters for the Create Log Source action |
protocol_parameters.id | number | Optional | Parameters for the Create Log Source action |
protocol_parameters.value | string | Optional | Parameters for the Create Log Source action |
protocol_parameters.name | string | Optional | Parameters for the Create Log Source action |
target_event_collector_id | number | Optional | Unique identifier |
log_source_extension_id | object | Optional | Unique identifier |
enabled | boolean | Optional | Parameter for Create Log Source |
coalesce_events | boolean | Optional | Parameter for Create Log Source |
name | string | Optional | Name of the resource |
wincollect_external_destination_ids | object | Optional | Unique identifier |
description | string | Optional | Parameter for Create Log Source |
sending_ip | object | Optional | Parameter for Create Log Source |
language_id | number | Optional | Unique identifier |
credibility | number | Optional | Parameter for Create Log Source |
last_event_time | number | Optional | Time value |
wincollect_internal_destination_id | object | Optional | Unique identifier |
average_eps | number | Optional | Parameter for Create Log Source |
disconnected_log_collector_id | object | Optional | Unique identifier |
requires_deploy | boolean | Optional | Parameter for Create Log Source |
auto_discovered | boolean | Optional | Parameter for Create Log Source |
type_id | number | Optional | Unique identifier |
protocol_type_id | number | Optional | Unique identifier |
Input Example
{"json_body":{"parsing_order":0,"internal":false,"gateway":false,"protocol_parameters":[{"id":0,"value":"facf:c4b8:9937:5f98:e78a:e48f:e34a:b143","name":"identifier"}],"target_event_collector_id":7,"log_source_extension_id":null,"enabled":true,"coalesce_events":true,"name":"Swinlane-test - facf:c4b8:9937:5f98:e78a:e48f:e34a:b","wincollect_external_destination_ids":null,"description":"Swinlane-test","sending_ip":null,"language_id":1,"credibility":8,"last_event_time":0,"wincollect_internal_destination_id":null,"average_eps":0,"disconnected_log_collector_id":null,"requires_deploy":true,"auto_discovered":false,"type_id":115,"protocol_type_id":0,"store_event_payload":true,"group_ids":[0]}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
sending_ip | object | Output field: sending_ip |
internal | boolean | Output field: internal |
protocol_parameters | array | Parameters for the Create Log Source action |
protocol_parameters.name | string | Parameters for the Create Log Source action |
protocol_parameters.id | number | Parameters for the Create Log Source action |
protocol_parameters.value | string | Parameters for the Create Log Source action |
description | string | Output field: description |
coalesce_events | boolean | Output field: coalesce_events |
enabled | boolean | Output field: enabled |
parsing_order | number | Output field: parsing_order |
average_eps | number | Output field: average_eps |
group_ids | array | Unique identifier |
credibility | number | Output field: credibility |
id | number | Unique identifier |
store_event_payload | boolean | Output field: store_event_payload |
target_event_collector_id | number | Unique identifier |
protocol_type_id | number | Unique identifier |
language_id | number | Unique identifier |
creation_date | number | Date value |
wincollect_external_destination_ids | object | Unique identifier |
log_source_extension_id | object | Unique identifier |
name | string | Name of the resource |
modified_date | number | Date value |
Output Example
{"sending_ip":{},"internal":true,"protocol_parameters":[{"name":"Example Name","id":123,"value":"string"}],"description":"string","coalesce_events":true,"enabled":true,"parsing_order":123,"average_eps":123,"group_ids":[123],"credibility":123,"id":123,"store_event_payload":true,"target_event_collector_id":123,"protocol_type_id":123,"language_id":123}
Get Log Sources
Obtain a comprehensive list of log sources from IBM QRadar for improved analysis and monitoring.
Endpoint
- URL: api/config/event_sources/log_source_management/log_sources
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.fields | string | Optional | Parameters for the Get Log Sources action |
parameters.filter | string | Optional | Parameters for the Get Log Sources action |
parameters.sort | string | Optional | Parameters for the Get Log Sources action |
headers | object | Optional | HTTP headers for the request |
headers.range | string | Optional | HTTP headers for the request |
headers.x-qrd-encryption-algorithm | string | Optional | HTTP headers for the request |
headers.x-qrd-encryption-password | string | Optional | HTTP headers for the request |
Input Example
{"parameters":{"fields":"field_one (field_two, field_three),field_four","filter":"field_one = 'String' and field_two > 42 or not field_three in (1, 2, 3)","sort":"+field_one,-object(sub_field)"},"headers":{"range":"items=0-49","x-qrd-encryption-algorithm":"AES256","x-qrd-encryption-password":"testpassword"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
[]
Patch Log Sources
Apply patches to multiple log sources in IBM QRadar, enabling creation, updates, and deletions in one transaction. Returns a task resource location.
Endpoint
- URL: api/config/event_sources/log_source_management/log_sources
- Method: PATCH
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{}
Get Offenses
Pulls a detailed list of offenses from IBM QRadar for in-depth analysis and monitoring.
Endpoint
- URL: api/siem/offenses
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
headers | object | Optional | HTTP headers for the request |
headers.Range | string | Optional | Use this parameter to restrict the number of elements that are returned in the list to a specified range. |
parameters.filter | string | Optional | This parameter is used to restrict the elements in a list base on the contents of various fields. |
parameters.sort | string | Optional | This parameter is used to sort the elements in a list. |
parameters.fields | string | Optional | Use this parameter to specify which fields you would like to get back in the response. |
Input Example
{"parameters":{"filter":"last_persisted_time >= 1668526028000","sort":"+field_one,-object(sub_field)","fields":"field_one (field_two, field_three),field_four"},"headers":{"Range":"items=0-49"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
[]
Get Offense By ID
Retrieve detailed properties of a specific offense in IBM QRadar using the provided offense ID.
Endpoint
- URL: api/siem/offenses/{{offense_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.offense_id | number | Required | Parameters for the Get Offense By ID action |
parameters.fields | string | Optional | Parameters for the Get Offense By ID action |
Input Example
{"parameters":{"fields":"field_one (field_two, field_three),field_four"},"path_parameters":{"offense_id":7544}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
last_persisted_time | number | Time value |
username_count | number | Name of the resource |
description | string | Output field: description |
rules | array | Output field: rules |
rules.id | number | Unique identifier |
rules.type | string | Type of the resource |
event_count | number | Count value |
flow_count | number | Count value |
assigned_to | object | Output field: assigned_to |
security_category_count | number | Count value |
follow_up | boolean | Output field: follow_up |
source_address_ids | array | Unique identifier |
source_count | number | Count value |
inactive | boolean | Output field: inactive |
protected | boolean | Output field: protected |
closing_user | string | Output field: closing_user |
destination_networks | array | Output field: destination_networks |
source_network | string | Output field: source_network |
category_count | number | Count value |
close_time | number | Time value |
remote_destination_count | number | Count value |
start_time | number | Time value |
magnitude | number | Output field: magnitude |
Output Example
{"last_persisted_time":123,"username_count":123,"description":"string","rules":[{"id":123,"type":"string"}],"event_count":123,"flow_count":123,"assigned_to":{},"security_category_count":123,"follow_up":true,"source_address_ids":[123],"source_count":123,"inactive":true,"protected":true,"closing_user":"string","destination_networks":["string"]}
Create Offense Note
Create a custom note for a specified offense in IBM QRadar using the unique offense ID and provided note text.
Endpoint
- URL: api/siem/offenses/{{offense_id}}/notes
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.offense_id | number | Required | Parameters for the Create Offense Note action |
parameters.note_text | string | Required | Parameters for the Create Offense Note action |
parameters.fields | string | Optional | Parameters for the Create Offense Note action |
Input Example
{"parameters":{"note_text":"Test note","fields":"field_one (field_two, field_three),field_four"},"path_parameters":{"offense_id":7544}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
note_text | string | Output field: note_text |
create_time | number | Time value |
id | number | Unique identifier |
username | string | Name of the resource |
Output Example
{"note_text":"string","create_time":123,"id":123,"username":"Example Name"}
Get Offense Notes
Retrieve all notes linked to a specific offense in IBM QRadar using the 'offense_id'.
Endpoint
- URL: api/siem/offenses/{{offense_id}}/notes
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.offense_id | number | Required | Parameters for the Get Offense Notes action |
headers | object | Optional | HTTP headers for the request |
headers.range | string | Optional | HTTP headers for the request |
parameters.fields | string | Optional | Parameters for the Get Offense Notes action |
parameters.filter | string | Optional | Parameters for the Get Offense Notes action |
Input Example
{"parameters":{"fields":"field_one (field_two, field_three),field_four","filter":"field_one = 'String' and field_two > 42 or not field_three in (1, 2, 3)"},"path_parameters":{"offense_id":7544},"headers":{"range":"items=0-49"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
[]
Update Offense
Update an existing offense in IBM QRadar using the specified offense ID.
Endpoint
- URL: api/siem/offenses/{{offense_id}}
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.offense_id | number | Required | Parameters for the Update Offense action |
parameters.assigned_to | string | Optional | Parameters for the Update Offense action |
parameters.closing_reason_id | number | Optional | Parameters for the Update Offense action |
parameters.fields | string | Optional | Parameters for the Update Offense action |
parameters.follow_up | boolean | Optional | Parameters for the Update Offense action |
parameters.protected | boolean | Optional | Parameters for the Update Offense action |
parameters.status | string | Optional | Parameters for the Update Offense action |
Input Example
{"parameters":{"assigned_to":"username","closing_reason_id":42,"fields":"field_one (field_two, field_three),field_four","follow_up":true,"protected":true,"status":"OPEN"},"path_parameters":{"offense_id":7544}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
last_persisted_time | number | Time value |
username_count | number | Name of the resource |
description | string | Output field: description |
rules | array | Output field: rules |
rules.id | number | Unique identifier |
rules.type | string | Type of the resource |
event_count | number | Count value |
flow_count | number | Count value |
assigned_to | object | Output field: assigned_to |
security_category_count | number | Count value |
follow_up | boolean | Output field: follow_up |
source_address_ids | array | Unique identifier |
source_count | number | Count value |
inactive | boolean | Output field: inactive |
protected | boolean | Output field: protected |
closing_user | string | Output field: closing_user |
destination_networks | array | Output field: destination_networks |
source_network | string | Output field: source_network |
category_count | number | Count value |
close_time | number | Time value |
remote_destination_count | number | Count value |
start_time | number | Time value |
magnitude | number | Output field: magnitude |
Output Example
{"last_persisted_time":123,"username_count":123,"description":"string","rules":[{"id":123,"type":"string"}],"event_count":123,"flow_count":123,"assigned_to":{},"security_category_count":123,"follow_up":true,"source_address_ids":[123],"source_count":123,"inactive":true,"protected":true,"closing_user":"string","destination_networks":["string"]}
Create Query
Initiate a new Ariel search in IBM QRadar using an AQL query expression with specified input parameters.
Endpoint
- URL: api/ariel/searches
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.query_expression | string | Optional | Parameters for the Create Query action |
parameters.saved_search_id | number | Optional | Parameters for the Create Query action |
Input Example
{"parameters":{"query_expression":"select sourceip from events","saved_search_id":42}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
cursor_id | string | Unique identifier |
status | string | Status value |
compressed_data_file_count | number | Response data |
compressed_data_total_size | number | Response data |
data_file_count | number | Response data |
data_total_size | number | Response data |
index_file_count | number | Count value |
index_total_size | number | Output field: index_total_size |
processed_record_count | number | Count value |
desired_retention_time_msec | number | Output field: desired_retention_time_msec |
progress | number | Output field: progress |
progress_details | array | Output field: progress_details |
progress_details.file_name | string | Name of the resource |
progress_details.file | string | Output field: progress_details.file |
query_execution_time | number | Time value |
query_string | string | Output field: query_string |
record_count | number | Count value |
size_on_disk | number | Output field: size_on_disk |
save_results | boolean | Result of the operation |
completed | boolean | Output field: completed |
subsearch_ids | array | Unique identifier |
subsearch_ids.file_name | string | Unique identifier |
subsearch_ids.file | string | Unique identifier |
Output Example
{"cursor_id":"string","status":"active","compressed_data_file_count":123,"compressed_data_total_size":123,"data_file_count":123,"data_total_size":123,"index_file_count":123,"index_total_size":123,"processed_record_count":123,"desired_retention_time_msec":123,"progress":123,"progress_details":[{"file_name":"Example Name","file":"string"}],"query_execution_time":123,"query_string":"string","record_count":123}
Get Query Results
Retrieve the results of a specific Ariel search in IBM QRadar using the provided unique search ID.
Endpoint
- URL: api/ariel/searches/{{search_id}}/results
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.search_id | string | Required | Parameters for the Get Query Results action |
headers | object | Optional | HTTP headers for the request |
headers.range | string | Optional | HTTP headers for the request |
Input Example
{"path_parameters":{"search_id":"f048831a-434a-448f-81c9-d0815e40fcca"},"headers":{"range":"items=0-49"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{}
Get Query Status
Retrieve the current status of a specific IBM QRadar query using the provided search ID.
Endpoint
- URL: api/ariel/searches/{{search_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.search_id | string | Required | Parameters for the Get Query Status action |
headers | object | Optional | HTTP headers for the request |
headers.Prefer | string | Optional | HTTP headers for the request |
Input Example
{"path_parameters":{"search_id":"24e5a350-5e21-43c4-9b33-56534895c833"},"headers":{"Prefer":"wait=1"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
cursor_id | string | Unique identifier |
status | string | Status value |
compressed_data_file_count | number | Response data |
compressed_data_total_size | number | Response data |
data_file_count | number | Response data |
data_total_size | number | Response data |
index_file_count | number | Count value |
index_total_size | number | Output field: index_total_size |
processed_record_count | number | Count value |
desired_retention_time_msec | number | Output field: desired_retention_time_msec |
progress | number | Output field: progress |
progress_details | array | Output field: progress_details |
progress_details.file_name | string | Name of the resource |
progress_details.file | string | Output field: progress_details.file |
query_execution_time | number | Time value |
query_string | string | Output field: query_string |
record_count | number | Count value |
size_on_disk | number | Output field: size_on_disk |
save_results | boolean | Result of the operation |
completed | boolean | Output field: completed |
subsearch_ids | array | Unique identifier |
subsearch_ids.file_name | string | Unique identifier |
subsearch_ids.file | string | Unique identifier |
Output Example
{"status_code":200,"response_headers":{"Server":"QRadar","Expires":"0, 0","Pragma":"no-cache, no-cache","Cache-Control":"no-cache, no-store, must-revalidate, no-cache, no-store, must-revalidate","X-XSS-Protection":"1; mode=block","X-Content-Type-Options":"nosniff","Strict-Transport-Security":"max-age=31536000; includeSubdomains;, max-age=31536000; includeSubDomains","Content-Type":"application/json;charset=UTF-8","X-Frame-Options":"SAMEORIGIN","Date":"Wed, 22 Feb 2023 16:03:38 GMT","Content-Leng...
Get Rule
Retrieve a specific security rule from IBM QRadar using the provided rule ID.
Endpoint
- URL: api/analytics/rules/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Get Rule action |
parameters.fields | string | Optional | Parameters for the Get Rule action |
Input Example
{"parameters":{"fields":"field_one (field_two, field_three),field_four"},"path_parameters":{"id":"100639"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
owner | string | Output field: owner |
identifier | string | Unique identifier |
base_host_id | number | Unique identifier |
capacity_timestamp | number | Output field: capacity_timestamp |
origin | string | Output field: origin |
creation_date | number | Date value |
type | string | Type of the resource |
enabled | boolean | Output field: enabled |
modification_date | number | Date value |
linked_rule_identifier | object | Unique identifier |
name | string | Name of the resource |
average_capacity | number | Output field: average_capacity |
id | number | Unique identifier |
base_capacity | number | Output field: base_capacity |
Output Example
{"owner":"string","identifier":"string","base_host_id":123,"capacity_timestamp":123,"origin":"string","creation_date":123,"type":"string","enabled":true,"modification_date":123,"linked_rule_identifier":{},"name":"Example Name","average_capacity":123,"id":123,"base_capacity":123}
Get Source Addresses
Retrieve a list of offense source addresses from IBM QRadar to identify active system threats.
Endpoint
- URL: api/siem/source_addresses
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.filter | string | Optional | Parameters for the Get Source Addresses action |
parameters.fields | string | Optional | Parameters for the Get Source Addresses action |
headers | object | Optional | HTTP headers for the request |
headers.range | string | Optional | HTTP headers for the request |
Input Example
{"parameters":{"filter":"first_event_flow_seen >= 1634663234343","fields":"field_one (field_two, field_three),field_four"},"headers":{"range":"items=0-49"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
[]
Response Headers
Header | Description | Example |
|---|---|---|
Cache-Control | Directives for caching mechanisms | no-cache, no-store, must-revalidate, no-cache, no-store, must-revalidate |
Connection | HTTP response header: Connection | keep-alive |
Content-Length | The length of the response body in bytes | 609 |
Content-Range | HTTP response header: Content-Range | ο»Ώ |
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Wed, 22 Feb 2023 16:03:38 GMT |
Expires | The date/time after which the response is considered stale | 0, 0 |
Location | URL of the LogSourceBulkTask resource to poll for operation status. | ο»Ώ |
Pragma | HTTP response header: Pragma | no-cache, no-cache |
Server | Information about the software used by the origin server | QRadar |
Set-Cookie | HTTP response header: Set-Cookie | JSESSIONID=C0DA0A55B56C0A3C3BD5C7C47F912A62; Path=/; Secure; HttpOnly;Secure;SameSite=Lax |
Strict-Transport-Security | HTTP response header: Strict-Transport-Security | max-age=31536000; includeSubdomains;, max-age=31536000; includeSubDomains |
Transfer-Encoding | HTTP response header: Transfer-Encoding | ο»Ώ |
X-Content-Type-Options | HTTP response header: X-Content-Type-Options | nosniff |
X-Frame-Options | HTTP response header: X-Frame-Options | SAMEORIGIN |
X-XSS-Protection | HTTP response header: X-XSS-Protection | 1; mode=block |