qradar data.md

For the complete documentation index, see llms.txt. Markdown versions of documentation pages are available by appending .md to page URLs; this page is available as Markdown.

QRadar

{% hint style="info" %} QRadar is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis. {% endhint %}

The Dropzone platform integrates with the IBM QRadar security SIEM. Many customers ingest other alert sources into QRadar (e.g. IDPs) and integrate Dropzone into QRadar rather than the source systems.

Create an API Key

QRadar requires an API key to enable.

To obtain an API Key, do the following:

Navigate to Admin

Navigate to User Management

Click on "Authorized Services"

Click "Add"

{% hint style="info" %} For conveniences sake, we recommend not assigning an expiration date for this API key, to prevent having to create a new one. {% endhint %}

Fill out token details

Copy the API-Key

Enable QRadar

To enable the Data Source integration, you will need the following information:

Dropzone Field Source
Server The same as your servername in your QRadar url, eg myserver/console/qradar
Port The standard html port, 443
API-Key The authorized service token value you generated earlier

Integrations Dropdown

Click Available

The QRadar Tile

The QRadar Data Configuration

If you have any errors engage your Dropzone AI support representative.