This article explains how to connect QRadar SIEM to Workbench.

Prerequisites

  1. Make sure you install the QRadar Use Case Manager application. The application supplies SOC analysts with an essential function that supports their operations.

Quick Links

Step 1: Enable Console Access

Having read-only access to the interface of your technology allows Expel to dig deeper during incident investigations. Our device health team uses this access to investigate potential health issues with your tech.

This procedure creates a user account for Expel that keeps the Expel activity separate from other activity on the QRadar SIEM console.

  1. Navigate to Admin > Users. A new window opens.

  2. Click +Add next to the search bar in the new window.

  3. Type a User Name.

  4. Complete User Description as you want.

  5. For E-mail type: soc+<Your_Organization_Name>@expel.io
    Be sure to include the "+" sign as part of the email address.

  6. Under Authentication, toggle Local Authentication Fallback on and type a password.

  7. Set the User Role and Security Profile to Admin.

  8. Click Save.

  9. Close the window.

Step 2: Enable API Access for Expel

This procedure creates an authentication token that allows the Expel Assembler to access the QRadar SIEM API.

  1. Navigate to Admin > Authorized Services. A new window opens.

  2. Click the Add Authorized Service in the Manage Authorized Services window.

  3. Type Expel API as the Service Name.

  4. Make sure the User Role and Security Profile are set to Admin.

  5. Select No Expiry.

  6. Click Create Service.

  7. Make note of the newly generated Authentication Token.

Step 3: Configure QRadar SIEM in Workbench

  1. Log in to Workbench.

  2. On the console page, navigate to Settings and click Security Devices.

  3. At the top right of the page, click Add Security Device.

  4. Search for and select QRadar SIEM.

    QRadar fields on the Add Security Devuice screen
    • (On-prem) Select the Assembler with a network connectivity to the QRadar SIEM device.

    • Name - enter the hostname of the QRadar SIEM device.

    • Location - enter the geographic location of the appliance.

    • Server address - enter the hostname or console IP of device.

    • API key - enter the Authentication Token created in step 2.

    • Use case manager ID - enter the numeric ID of the QRadar Use Case Manager application.

    • Username and Password - enter the credentials created in step 1.

  5. You can provide console access now or set it up later. Use the instructions below to set it up later.

You can see if the device is healthy on the Security Devices page. It may take a few minutes to see the device listed as healthy.

To check if alerts are coming through, navigate to Dashboards > Alert Analysis. Scroll to the device you want to check and select the Expel Alerts tab to reveal more alert information. It can take 36 to 72 hours for alerts to appear after setup, as we tune your device.

Step 4: Edit the Device to Add Console Access

Note

Expel secures all login information our SOC analysts need about your devices in an MFA password product. Access to this login information is protected using our internal MFA processes. Learn more about the IP addresses all Expel traffic comes from.

To configure console access within Workbench:

Note
Expel will poll only Offenses from QRadar, after which a further filtering according to our Detection Strategy will apply.