# QRadar

{% hint style="info" %}
QRadar is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis.
{% endhint %}

The Dropzone platform integrates with the [IBM QRadar](https://www.ibm.com/qradar) security SIEM. Many customers ingest other alert sources into QRadar (e.g. IDPs) and integrate Dropzone into QRadar rather than the source systems.

## Create an API Key

QRadar requires an API key to enable.

To obtain an API Key, do the following:

* In the upper bar in the QRadar Homepage, click "Admin"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-9f50fff0d51a95686979874c4582400cb46d708b%2Fqradar-integration-1.png?alt=media" alt=""><figcaption><p>Navigate to Admin</p></figcaption></figure>

* In the left hand bar, navigate to System Configuration > User Management

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-cd6a6830d1466541bce3358153877169bdc95eb7%2Fqradar-integration-2.png?alt=media" alt=""><figcaption><p>Navigate to User Management</p></figcaption></figure>

* Click on "Authorized Services"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-ed6bc19aca87a37dc12f5a81be51fa6bbad23652%2Fqradar-integration-3.png?alt=media" alt=""><figcaption><p>Click on "Authorized Services"</p></figcaption></figure>

* In the window that pops up, click "Add"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-0d553474d49539d202da943ed9604a443f363744%2Fqradar-integration-4.png?alt=media" alt=""><figcaption><p>Click "Add"</p></figcaption></figure>

* Under "Authorized Service Label," label the key something memorable, such as "dropzone\_ai"
* Select an Admin security profile
* Under "User Role, select "All"
* Under "Expiry Settings," assign an expiration date if you choose

{% hint style="info" %}
For conveniences sake, we recommend not assigning an expiration date for this API key, to prevent having to create a new one.
{% endhint %}

\* Click "Save"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-f5de3a0f90b85b4c2c1147a84dbdce824d7dfad8%2Fqradar-integration-5.png?alt=media" alt=""><figcaption><p>Fill out token details</p></figcaption></figure>

* Store the authorized service token in a safe location for use later in the Dropzone UI where it will be called "API-Key"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-cb59c214ab2033859639cd3b9d841e68869aa376%2Fqradar-integration-6.png?alt=media" alt=""><figcaption><p>Copy the API-Key</p></figcaption></figure>

## Enable QRadar

To enable the Alert Source integration, you will need the following information:

| Dropzone Field | Source                                                                       |
| -------------- | ---------------------------------------------------------------------------- |
| Server         | The same as your servername in your QRadar url, eg *myserver*/console/qradar |
| Port           | The standard html port, 443                                                  |
| API-Key        | The authorized service token value you generated earlier                     |

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.ai
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-b3f07f902b1402dadc7abbd8bb62f9c204547390%2Fui-integrations-dropdown.png?alt=media" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Available"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-434641ec6d4e45051842f86164f485d6bd289424%2Fapp_system_integrations_available.png?alt=media" alt=""><figcaption><p>Click Available</p></figcaption></figure>

* In the Search bar, search QRadar, then click "Configure"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-99dc85bd0e769d3c17a924f66a82b21bdd58185e%2Fapp_system_integrations_available_qradar.png?alt=media" alt=""><figcaption><p>The QRadar Tile</p></figcaption></figure>

* Under the Alert Source header, if your QRadar integration is behind an [On-premise Dropzone Connector](https://docs.dropzone.ai/platform/settings/connector), select your connector from the dropdown
* Input the Server, Port, and API-Key

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-709a075b5070f7581c88f9e68e08a0f2679158a0%2Fapp_system_integrations_available_qradar_alert_config.png?alt=media" alt=""><figcaption><p>The QRadar Alert Configuration (pt 1)</p></figcaption></figure>

* Under "Enabled QRadar Offense Statuses," check the box for each [offense status](https://www.ibm.com/docs/en/qradar-on-cloud?topic=management-offense-retention) you wish Dropzone to investigate alerts for

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-955736aaaf9ccb8b3bcb8dface6be9b2e09f8dfa%2Fapp_system_integrations_available_qradar_alert_config_1.png?alt=media" alt=""><figcaption><p>The QRadar Alert Configuration (pt 2)</p></figcaption></figure>

* Under "Title Exclusions," you may choose to exclude alerts by title. To do so, click "Add Item," then input a list of [Python regexes](https://docs.python.org/3/library/re.html) of the titles of the alerts you wish to exclude

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-59e880a11342a86c53e546c2fea8d02b469c7081%2Fapp_system_integrations_available_qradar_alert_config_3.png?alt=media" alt=""><figcaption><p>The QRadar Alert Configuration (pt 3)</p></figcaption></figure>

* Input your desired poll interval and lookback

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-2f782075588748125acc7521fef3474d85f4c527%2Fapp_system_integrations_available_qradar_alert_config_2.png?alt=media" alt=""><figcaption><p>The QRadar Alert Configuration (pt 4)</p></figcaption></figure>

* Click "Test & Save" to finish
