SIEM integration

Automate IBM QRadar SIEM with plain language

Read QRadar offenses, log sources and reference data, and add VernacSecure SuperBot™ findings to a reference set.

What you can do

IBM QRadar — Ariel / REST API v20

  • List offenses and their magnitude
  • Read log sources and rules
  • Add a value to a reference set

Connection: header authentication against https://qradar.example.com. Credentials are encrypted at rest, or prompted per action if you prefer never to store them.

Example

Ask in plain English

Prompt: “Show the last 24 hours of high severity alerts in IBM QRadar”

Result: VernacSecure SuperBot™ runs the search, normalises the results and offers follow-up actions on other integrations.

Get started free

Read actions
  • Fetch offenses — Lists open offenses.
  • Fetch log sources — Lists configured log sources.
  • Fetch rules — Lists correlation rules.
Write actions
  • Add to reference set — Adds the endpoint IP to a reference set.