Configure QRadar

Do this procedure to integrate a new TAXII feed into QRadar to enhance threat intelligence capabilities. This procedure covers adding the feed, ensuring full indicator ingestion, and monitoring the integration via the Activity Log for optimal security posture.

About this task

Note:
The Threat Intelligence application version 2.4.2, and earlier, has a bug that can lead to only partial ingestion of the Trusted Automated Exchange of Indicator Information (TAXII) data. IBM is aware of the bug.

Procedure

  1. Download QRadar from the IBM website.
  2. Go to Admin > Extensions Management.


  3. Select All items.
  4. Make sure that you have the latest version of the Threat Intelligence app installed.


  5. Select Threat Intelligence.


  6. Select Feeds Downloader.
  7. Select Add Threat Feed > Add TAXII Feed.


  8. In the Connection page, in the Version dropdown, select TAXII 2.0.


  9. Enter the details as necessary in the other fields. Make sure the endpoint string has /root/collections at the end.
  10. Select Discover.
  11. Select Parameter.
  12. From the Collections dropdown, select the applicable option.


  13. From the Observable Type dropdown, select the applicable indicator type.
  14. To the right of Reference Set Management, select Add.
  15. In the bottom right section, select Next.
  16. In the Summary page, select Save.


  17. You can now select Poll Now to force the indicator collection.


Results

QRadar has been configured.