Integrate RevealX 360 with QRadar SOAR
This integration enables IBM Security QRadar SOAR to export device and detection data from the ExtraHop system through the ExtraHop REST API. You can view exported data in QRadar SOAR to gain insight into how your devices are communicating in your environment and to view network threat detections.
Before you begin
You must meet the following system requirements:
- ExtraHop RevealX 360
- Your user account must have privileges on RevealX 360 for System and Access Administration.
- Your RevealX 360 system must be connected to an ExtraHop sensor with firmware version 9.6 or later.
- Your RevealX 360 system must be connected to ExtraHop Cloud Services.
- QRadar SOAR
- You must have QRadar SOAR version 46.0 or later
-
Complete the following steps to create ExtraHop REST API credentials for the
integration:
-
Complete the following steps to install and configure the ExtraHop app for
QRadar SOAR:
Thank you for your feedback. Can we contact you to ask follow up questions?