Integrate Reveal(x) 360 with QRadar SOAR
This integration enables IBM Security QRadar SOAR to export device and detection data from the ExtraHop system through the ExtraHop REST API. You can view exported data in QRadar SOAR to gain insight into how your devices are communicating in your environment and to view network threat detections.
Before you begin
You must meet the following system requirements:
- ExtraHop Reveal(x) 360
- Your user account must have privileges on Reveal(x) 360 for System and Access Administration.
- Your Reveal(x) 360 system must be connected to an ExtraHop sensor with firmware version 9.6 or later.
- Your Reveal(x) 360 system must be connected to ExtraHop Cloud Services.
- QRadar SOAR
- You must have QRadar SOAR version 46.0 or later
-
Complete the following steps to create ExtraHop REST API credentials for the
integration:
-
Complete the following steps to install and configure the ExtraHop app for
QRadar SOAR:
Thank you for your feedback. Can we contact you to ask follow up questions?