SIEM integration
Automate IBM QRadar SIEM with plain language
Read QRadar offenses, log sources and reference data, and add VernacSecure SuperBot™ findings to a reference set.
What you can do
IBM QRadar — Ariel / REST API v20
- List offenses and their magnitude
- Read log sources and rules
- Add a value to a reference set
Connection: header authentication against https://qradar.example.com. Credentials are encrypted at rest, or prompted per action if you prefer never to store them.
Example
Ask in plain English
Prompt: “Show the last 24 hours of high severity alerts in IBM QRadar”
Result: VernacSecure SuperBot™ runs the search, normalises the results and offers follow-up actions on other integrations.
Read actions
- Fetch offenses — Lists open offenses.
- Fetch log sources — Lists configured log sources.
- Fetch rules — Lists correlation rules.
Write actions
- Add to reference set — Adds the endpoint IP to a reference set.
Related siem automation pages
Armor Point · Datadog Cloud SIEM · Devo Platform · Elastic Security · Exabeam Security Operations · Fortinet FortiSIEM