> For the complete documentation index, see [llms.txt](https://docs.dropzone.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.dropzone.ai/integrations/alert/qradar_alert.md).

# QRadar

{% hint style="info" %}
QRadar is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis.
{% endhint %}

The Dropzone platform integrates with the [IBM QRadar](https://www.ibm.com/qradar) security SIEM. Many customers ingest other alert sources into QRadar (e.g. IDPs) and integrate Dropzone into QRadar rather than the source systems.

## Create an API Key

QRadar requires an API key to enable.

To obtain an API Key, do the following:

* In the upper bar in the QRadar Homepage, click "Admin"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-5afd6a1335321e2b6ed7568fa6b27eefe49bae25%2Fqradar-integration-1.png?alt=media" alt=""><figcaption><p>Navigate to Admin</p></figcaption></figure>

* In the left hand bar, navigate to System Configuration > User Management

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-6a80e4259ec9c8cdadf79f8b225cfe706b3abea1%2Fqradar-integration-2.png?alt=media" alt=""><figcaption><p>Navigate to User Management</p></figcaption></figure>

* Click on "Authorized Services"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-8f0412b511d2346d53d3530b08beef275c13004d%2Fqradar-integration-3.png?alt=media" alt=""><figcaption><p>Click on "Authorized Services"</p></figcaption></figure>

* In the window that pops up, click "Add"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-a7338d71404a5f37f131d9f3406cd60b3a7377c6%2Fqradar-integration-4.png?alt=media" alt=""><figcaption><p>Click "Add"</p></figcaption></figure>

* Under "Authorized Service Label," label the key something memorable, such as "dropzone\_ai"
* Select an Admin security profile
* Under "User Role, select "All"
* Under "Expiry Settings," assign an expiration date if you choose

{% hint style="info" %}
For conveniences sake, we recommend not assigning an expiration date for this API key, to prevent having to create a new one.
{% endhint %}

* Click "Save"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-f9ec5e2f9eecc9a9f27615e461672f238ebd639b%2Fqradar-integration-5.png?alt=media" alt=""><figcaption><p>Fill out token details</p></figcaption></figure>

* Store the authorized service token in a safe location for use later in the Dropzone UI where it will be called "API-Key"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-2ccdf7f8a4f7693dfee619e20e584dae2e2842bd%2Fqradar-integration-6.png?alt=media" alt=""><figcaption><p>Copy the API-Key</p></figcaption></figure>

## Enable QRadar

To enable the Alert Source integration, you will need the following information:

| Dropzone Field | Source                                                                       |
| -------------- | ---------------------------------------------------------------------------- |
| Server         | The same as your servername in your QRadar url, eg *myserver*/console/qradar |
| Port           | The standard html port, 443                                                  |
| API-Key        | The authorized service token value you generated earlier                     |

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.ai
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-8c77435ef341f8180540e049f505d3390a27bbf4%2Fui-integrations-dropdown.png?alt=media" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-7e038b4f51ee27d4cf4f1ac6f76c5ddae2bf29c5%2Fapp_system_integrations_library.png?alt=media" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search QRadar, then click "Configure"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-c3623b9e4fbd76080866ba17a0197ae4937b118f%2Fapp_system_integrations_available_qradar.png?alt=media" alt=""><figcaption><p>The QRadar Tile</p></figcaption></figure>

* Under the Alert Source header, if your QRadar integration is behind an [On-premise Dropzone Connector](https://docs.dropzone.ai/platform/settings/connector), select your connector from the dropdown
* Input the Server, Port, and API-Key

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-ee48a5775a7ed32b764d6ea79059ee42d8558e8e%2Fapp_system_integrations_available_qradar_alert_config.png?alt=media" alt=""><figcaption><p>The QRadar Alert Source Configuration (pt 1)</p></figcaption></figure>

* Under "Enabled QRadar Offense Statuses," check the box for each [offense status](https://www.ibm.com/docs/en/qradar-on-cloud?topic=management-offense-retention) you wish Dropzone to investigate alerts for

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-82aabc7619d8e01f370c7e65862f15ac27bc148b%2Fapp_system_integrations_available_qradar_alert_config_1.png?alt=media" alt=""><figcaption><p>The QRadar Alert Source Configuration (pt 2)</p></figcaption></figure>

* Under "Title Exclusions," you may choose to exclude alerts by title. To do so, click "Add Item," then input a list of [Python regexes](https://docs.python.org/3/library/re.html) of the titles of the alerts you wish to exclude

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-a82c97f0c742f77c82866d85ae48bcb636d16aeb%2Fapp_system_integrations_available_qradar_alert_config_3.png?alt=media" alt=""><figcaption><p>The QRadar Alert Source Configuration (pt 3)</p></figcaption></figure>

* Input your desired poll interval and lookback

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-79ab9c397241eb165f5157db81131207481ef1c3%2Fpoll-interval-lookback.png?alt=media" alt=""><figcaption><p>The QRadar Alert Source Configuration (pt 4)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-43a55827dfbfd5a9af3d744a16e7e8306fc8e253%2Fadvanced-filtering-test-save.png?alt=media" alt=""><figcaption><p>The QRadar Alert Source Configuration (pt 5)</p></figcaption></figure>

* Click "Test & Save" to finish
