Overview
The IBM QRadar integration enables ThreatAware to collect and monitor security data from your IBM QRadar environment, providing comprehensive visibility and threat detection capabilities.Connection Method: API
Setup Time: 15 minutes
Access Required: IBM QRadar Administrator account
Setup instructions
1
Log in to IBM QRadar Console
- Access the IBM QRadar Console using an account with administrator privileges.
2
Create an Authorized Service for API Access
- In the QRadar console, go to Admin > Authorized Services.
- Click Add Authorized Service and create a new service specifically for ThreatAware integration.
- Set the required permissions, typically Read-only for monitoring purposes, unless ThreatAware requires broader access.
- Save and copy the Service Token generated.
3
Input API Token in ThreatAware
- Open ThreatAware, go to Integrations, and select IBM QRadar.
- Enter the Service Token and QRadar Console URL in their respective fields.
Required credentials
Service Token
Service Token
Token created for API access in IBM QRadar.
QRadar Console URL
QRadar Console URL
URL of your IBM QRadar instance.
Troubleshooting
Verification
Verification
In ThreatAware, ensure the Integration Status shows as Active after setup.
Troubleshooting
Troubleshooting
- Invalid Token: Verify that the Service Token is entered accurately.
- Permission Denied: Ensure the Service Token has the necessary permissions configured for ThreatAware access in IBM QRadar.
Important notes
- For more information on permissions and configuration, refer to the IBM QRadar API Documentation.
- Keep the Service Token secure, as it allows access to IBM QRadar data.