IBM / IBM-QRadar-Universal-Cloud-REST-API

These workflows are provided for sample usage, new submissions and updates from the community, and are NOT supported by IBM.
44 stars 89 forks source link

IBM QRadar Universal Cloud Connector

IBM Security QRadar is pleased to announce the release of the Universal Cloud Connector, which is designed to enable security teams to more easily ingest data from a wide range of REST API cloud-based applications and services for enhanced visibility. To address this new dynamic, the Universal Cloud Connector includes a new Universal Cloud REST API Protocol that enables you to create log sources for the acquisition of data from REST API compatible data sources that aren’t currently supported. With the Universal Cloud REST API Protocol, you can:

Before you begin

QRadar currently integrates with approximately 450 third-party devices. However, as organizations adapt to new technology, there is an immediate need to monitor network traffic for new data sources. As an example, I’ll walk you through how to easily ingest data from a third party service, Duo Security.

Note the following terminology as you configure the Universal Cloud REST API:

Issues

For any issues with sample workflows in this repository please make use of the Issues feature in Github. If you have questions that aren't getting a response a good tip is to tag the original contributor and see if they can offer some feedback. This is community supported so all users are encouraged to provide assistance and support their peers in the community.

Contributing

For instructions on how to contribute your own workflow to this repository, refer to the CONTRIBUTING.md file.

Configuration Documentation

Universal Cloud REST API configuration documentation and be found here: https://www.ibm.com/support/knowledgecenter/SS42VS_DSM/com.ibm.dsm.doc/c_universal_rest_overview.html?cp=SS42VS_7.4