IBM QRadar Integration¶
Integration Architecture¶
The integration flow enables alert forwarding from AccuKnox to IBM QRadar. Alerts generated in the AccuKnox UI, sourced from findings and various alert sources, are processed by a rules engine and triggers according to the configured settings. These alerts are then transported via a webhook server set up in the customer environment, using the Syslog protocol to forward them to IBM QRadar, which serves as the final destination for receiving the alerts.

Architecture Components¶
- AccuKnox platform (source)
- Webhook server (intermediary)
- Syslog protocol (transport)
- IBM QRadar (destination)
Customer Integration Process¶
- Configure webhook in AccuKnox (See Webhook Integration Guide).
- Set up QRadar configuration (customer responsibility).
- Report configuration completion back to AccuKnox.
Connector and Send Event¶
-
Log in to QRadar as
Admin.
-
Click
Adminand thenData Source.
-
Click
Log Source.
-
Click
+ New Source Log->Single Source.

-
Configurations:
- Select Log Source Type -
Universal DSM - Select a Protocol -
Syslog - Name -
Test Qradar - Log Source Identifier -
192.168.1.226(Source IP from which Log is forwarded to Qradar)

- Select Log Source Type -
-
Go back to
Adminagain to deploy changes. ClickDeploy Changes, wait for changes to be deployed.

-
Now go to
Log Activityto see All Alerts. -
Now trigger the Event. You will be alerted in real-time in the Qradar UI.
-
Test Event

-
Event in Qradar UI



-
Check QRadar IP¶
- Go to Admin.
- Click System Configuration.
-
Click
System and License Management.
