Thank you for your feedback.
Form temporarily unavailable. Please try again or contact docfeedback@servicenow.com to submit your comments.
Versions
  • London
  • Kingston
  • Jakarta
  • Istanbul
  • Helsinki
  • Geneva
  • Store
Close

Collect QRadar Configurations activity

Collect QRadar Configurations activity

The Collect QRadar Configurations workflow activity gathers configuration information to use in the workflow.

The Collect QRadar Configurations activity can be used with any workflow to gather the IBM QRadar configuration settings.

Results

Possible results for this activity are:

Table 1. Results
Result Description
Success Configuration succeeded. .
Failure An error occurred while attempting to verify the configuration. More error information is available in the activity output error.

Input variables

Input variables determine the initial behavior of the activity.

Variable Description
source Source of the request to run the workflow. Supported inputs are: Trusted Security Circles or security incident task.
days_to_search Days to search from the current day backwards. Default is 7.
max_rows Maximum rows to return from the query. The limit depends on the third-party integration.
observables The list of observables from Trusted Security Circles or the security incident task to search for. Returned in JSON format.
query Search syntax. $(observable) is the default.

Output variables

The output variables contain data that can be used in subsequent activities.

Table 2. Output variables
Variable Description
endpoint_base Base URL of the third-party integration API.
link_endpoint_base Link to an IBM QRadar instance, when available.
use_default_workflows Determines whether to use the workflow that was installed with the plugin or not. Possible values are true and false..
elastic_username Qradar user name
elastic_password QRadar password
source Source of the request to run the workflow. Supported inputs are: Trusted Security Circles or security incident task.
max_rows Maximum rows to return from the query. The limit depends on the third-party integration. .
days_to_search Days to search from the current day backwards. Default is 7.
query Search syntax. $(observable) is the default.