Dropzone AI Documentation
WebsiteTest Drive
  • Dropzone Documentation
  • Overview
    • Alert Sources
    • Data Sources
    • Communicators
    • On-prem Support - Dropzone Connector
    • Interactive Chat
    • Metrics Guide
  • Dropzone Administraton
    • Team Admin
      • Google Workspace SAML
      • Okta SAML
  • Dropzone Integrations
    • Alert + Data Source Integrations
      • Amazon Web Services (AWS)
        • Cross-Account Access via CloudFormation
        • Cross-Account Access via Console
      • CrowdStrike
      • Datadog
      • Elasticsearch
      • Google Workspace
      • Google GCP
      • Jira
      • Microsoft 365 / Microsoft Defender
      • Palo Alto Networks Firewall
      • Panther
      • SentinelOne
      • Splunk
      • Sumo Logic
    • Alert Integrations
      • Gem
    • Communicators
      • Slack Communicator
    • Data Source Integrations
      • AbuseIPDB
      • Active Directory (LDAP)
      • Archive Inspector
      • Blocklist.de
      • CAPA
      • Censys
      • Crowdstrike Falcon Intelligence
      • DNSResolver
      • File
      • GreyNoise
      • Hybrid Analysis
      • Host.io
      • IPInfo.io
      • IPQualityScore
      • MalwareBazaar
      • Nuclei
      • NVD
      • Okta
      • oletools
      • OpenSSL Sign Code
      • PDF Analysis
      • Perplexity AI
      • PhishTank
      • Shodan
      • TShark
      • QRadar
      • UnshortenMe
      • URLhaus
      • Urlscan.io
      • VirusTotal
      • Vision
      • WHOIS
      • YARAify
Powered by GitBook
On this page
  • Create an API Key
  • Enable QRadar

Was this helpful?

  1. Dropzone Integrations
  2. Data Source Integrations

QRadar

PreviousTSharkNextUnshortenMe

Last updated 2 months ago

Was this helpful?

QRadar is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis.

The Dropzone platform integrates with the security SIEM. Many customers ingest other alert sources into QRadar (e.g. IDPs) and integrate Dropzone into QRadar rather than the source systems.

Create an API Key

QRadar requires an API key to enable.

To obtain an API Key, do the following:

  • In the upper bar in the QRadar Homepage, click "Admin"

  • In the left hand bar, navigate to System Configuration > User Management

  • Click on "Authorized Services"

  • In the window that spawns, click "Add"

  • Under "Authorized Service Label", label the key something memorable, such as "dropzone_ai"

  • Select an Admin security profile

  • Under "User Role, select "All"

  • Under "Expiry Settings", assign an expiration date if you choose

We recommend not assigning an expiration date for this API key, to prevent having to create a new one.

* Click "Save"

  • Store the authorized service token in a safe location for use later in the Dropzone UI where it will be called "API-Key"

Enable QRadar

To enable the Data Source integration, you will need the following information:

Dropzone Field
Source

Server

The same as your company server url in QRadar, eg myserver/console/qradar

Port

The standard html port, 443

API-Key

The authorized service token value you generated earlier

  • Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.ai

  • Click System > Integrations

  • Click "Available"

  • In the Search bar, search QRadar, then click "Configure"

  • Input the Server, Port, and API-Key

  • Under "Ignored Log Sources", you may add log sources to ignore in Dropzone searches

  • Click "Test & Save" to finish

If you have any errors engage your Dropzone AI support representative.

IBM QRadar
Navigate to Admin
Navigate to User Management
Click on "Authorized Services"
Click "Add"
Fill out token details
Copy the API-Key
Integrations Dropdown
Click Available
The QRadar Data Tile
The QRadar Configuration