QDATA LDAP Data Enrichment For QRadar Admin Guide 2.0.6
QDATA LDAP Data Enrichment For QRadar Admin Guide 2.0.6
www.scnsoft.com
QRadar SIEM: Admin Guide
QDATA
LDAP DATA ENRICHMENT
FOR IBM SECURITY
QRADAR SIEM
ADMIN GUIDE
Table of Contents
Overview ........................................................................................................................................ 3
Supported Versions ...................................................................................................................... 4
QDATA LDAP Data Enrichment Installation ................................................................................ 5
Downloading QDATA App ............................................................................................................................. 5
Installing QDATA App ................................................................................................................................... 5
Configuring QDATA App ............................................................................................................................... 5
Usage ............................................................................................................................................. 6
Adding New Import Task ............................................................................................................................... 6
Naming the Reference Table Fields .............................................................................................................. 8
Working with Tasks ....................................................................................................................................... 8
Backup / Restore........................................................................................................................... 9
Troubleshooting............................................................................................................................ 9
Appendix A: Release notes ........................................................................................................ 10
2.0.0 ........................................................................................................................................................ 10
2.0.1 ........................................................................................................................................................ 10
2.0.2 ........................................................................................................................................................ 10
2.0.3 ........................................................................................................................................................ 10
2.0.4 ........................................................................................................................................................ 10
2.0.5 ........................................................................................................................................................ 10
2.0.6 ........................................................................................................................................................ 10
Overview
QDATA LDAP Data Enrichment for IBM Security QRadar SIEM (hereinafter QDATA App), is QRadar extension
to synchronize QRadar Reference Sets and Tables content with information from Active Directory or any other
LDAP-based storage.
QDATA App supports multiple tasks with either periodic or scheduled sync at specific time of the day,
complex LDAP queries, advanced configuration, per-task statistics and in-app logging.
QDATA App perfectly fit scenario when you need to develop a correlation rule to be triggered on user action
from specific account type or group.
Using simple flat list with usernames (reference set), it’s just a matter of configuring proper LDAP query in
QDATA App and adding something like “when any of Username are contained in any of
Corp_Admin_Accounts” as rule test.
QDATA App is a free tool and available under Apache 2 license. Full text of the license is available on the
official website: https://www.apache.org/licenses/LICENSE-2.0
Supported Versions
Supported QRadar versions are:
7.4.2 and higher
NOTE: QDATA App is developed by ScienceSoft Inc. and not supported by IBM. You can request your own
custom QRadar app to be developed, request QRadar profession services or get support for this particular
app via following email address: [email protected].
Usage
Adding New Import Task
Follow steps below to add new import task:
19. Time - (applies only when Run value is At) – set time
20. Days - (applies only when Run value is At) – set the number of days between runs
Press Save button to save configuration
Backup / Restore
To backup/restore your configuration press Gear button and select the action desired:
Notice: Due to security considerations Authentication Token and Configuration passwords are not included
into backup file. You will need to re-enter all passwords after the restoration process is over.
Troubleshooting
If you have any problems with QDATA App execution then you can contact the support team:
[email protected]
To download application’s log files press Gear button at the top of the windows
2.0.1
NLS support added for filters
Security fixes
2.0.2
Backup/Restore feature added
2.0.3
Error reporting improved
2.0.4
Skip incomplete entries feature added
2.0.5
Reference Table fields naming added
2.0.6
Fixed compatibility issues for QRadar v.7.3.3