QRadar
Create an API Key






Enable QRadar
Dropzone Field
Source








Last updated
Was this helpful?
QRadar is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis.
The Dropzone platform integrates with the IBM QRadar security SIEM. Many customers ingest other alert sources into QRadar (e.g. IDPs) and integrate Dropzone into QRadar rather than the source systems.
QRadar requires an API key to enable.
To obtain an API Key, do the following:
In the upper bar in the QRadar Homepage, click "Admin"

In the left hand bar, navigate to System Configuration > User Management

Click on "Authorized Services"

In the window that pops up, click "Add"

Under "Authorized Service Label," label the key something memorable, such as "dropzone_ai"
Select an Admin security profile
Under "User Role, select "All"
Under "Expiry Settings," assign an expiration date if you choose
For conveniences sake, we recommend not assigning an expiration date for this API key, to prevent having to create a new one.
* Click "Save"

Store the authorized service token in a safe location for use later in the Dropzone UI where it will be called "API-Key"

To enable the Alert Source integration, you will need the following information:
Server
The same as your servername in your QRadar url, eg myserver/console/qradar
Port
The standard html port, 443
API-Key
The authorized service token value you generated earlier
Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.ai
In the bottom left hand corner, navigate to Settings > Integrations

Click "Available"

In the Search bar, search QRadar, then click "Configure"

Under the Alert Source header, if your QRadar integration is behind an On-premise Dropzone Connector, select your connector from the dropdown
Input the Server, Port, and API-Key

Under "Enabled QRadar Offense Statuses," check the box for each offense status you wish Dropzone to investigate alerts for

Under "Title Exclusions," you may choose to exclude alerts by title. To do so, click "Add Item," then input a list of Python regexes of the titles of the alerts you wish to exclude

Input your desired poll interval and lookback

If you wish to further filter alerts using the Python CEL package, check the box labeled "Use advanced filtering"
Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
Contact your Dropzone AI support representative for more information about this feature

Click "Test & Save" to finish
Last updated
Was this helpful?
Was this helpful?