IBM QRadar is an enterprise SIEM platform that collects, normalizes, and correlates log and network flow data from across the IT environment to detect threats, support investigations, and meet compliance requirements.
Organizations building an IBM QRadar integration can use Synqly to route normalized security findings, alerts, and events into QRadar for correlation and threat detection. Integrate IBM QRadar to connect third-party security data sources without custom log source configuration for every tool.
Configuration for IBM QRadar SIEM.
[Configuration guide](https://docs.synqly.com/guides/provider-configuration/qradar-setup)
Integration Use Cases
Get Investigation
Retrieves an investigation by ID.
Post Events
Writes a batch of `Event` objects to the SIEM configured with the token used for authentication.
Query Alerts
Queries alerts from the SIEM configured with the token used for authentication.
Query Events
Queries events from the SIEM configured with the token used for authentication.
Query Investigations
Queries investigations
Query Log Providers
Queries available log providers in the source SIEM