Skip to main content

Overview

The IBM QRadar integration enables ThreatAware to collect and monitor security data from your IBM QRadar environment, providing comprehensive visibility and threat detection capabilities.
Connection Method: API Setup Time: 15 minutes Access Required: IBM QRadar Administrator account

Setup instructions

1

Log in to IBM QRadar Console

2

Create an Authorized Service for API Access

  • In the QRadar console, go to Admin > Authorized Services.
  • Click Add Authorized Service and create a new service specifically for ThreatAware integration.
  • Set the required permissions, typically Read-only for monitoring purposes, unless ThreatAware requires broader access.
  • Save and copy the Service Token generated.
3

Input API Token in ThreatAware

  • Open ThreatAware, go to Integrations, and select IBM QRadar.
  • Enter the Service Token and QRadar Console URL in their respective fields.

Required credentials

Token created for API access in IBM QRadar.
URL of your IBM QRadar instance.

Troubleshooting

In ThreatAware, ensure the Integration Status shows as Active after setup.
  • Invalid Token: Verify that the Service Token is entered accurately.
  • Permission Denied: Ensure the Service Token has the necessary permissions configured for ThreatAware access in IBM QRadar.

Important notes

  • For more information on permissions and configuration, refer to the IBM QRadar API Documentation.
  • Keep the Service Token secure, as it allows access to IBM QRadar data.