# Integrate OpManager with IBM QRadar OpManager integrates with IBM QRadar, a SIEM platform that enables detailed analysis of network events and security logs. With this integration, you can forward events through UDP protocol/syslogs from OpManager to QRadar in real time, strengthening threat detection, improving incident response to potential threats, and reducing downtime. **IBM QRadar Configuration** 1. [Steps to configure in IBM](https://www.manageengine.com/network-monitoring/help/configure-opm-ibm-qradar.html#steps) **OpManager Configuration** 1. [Configure Audit and Access logs](https://www.manageengine.com/network-monitoring/help/configure-opm-ibm-qradar.html#logs) 2. [Associate a Notification Profile](https://www.manageengine.com/network-monitoring/help/configure-opm-ibm-qradar.html#np) ## IBM QRadar Configuration #### **Steps to configure in IBM** - Go to Log Sources, click on **New Log Sources**, and choose **Single** or **Multiple Log Sources** based on whether syslogs are coming from one or multiple sources. ![OpManager -IBM](https://www.manageengine.com/network-monitoring/help/images/ibm-01.png) - Set the **Log Source Type** to **Universal DSM**. - Select the **Protocol Type** as **Syslog**. - You can configure the log sources by providing the name, description, and other fields. These fields are optional. ![OpManager -IBM](https://www.manageengine.com/network-monitoring/help/images/ibm-2.png) - Configure the protocol parameters by specifying the OpManager server host. Select **'Multi Source'** to add multiple IPs or hostnames. - Click on **Finish** and deploy the applied changes under **Admin**. - Once deployed, you can proceed with the setup through the OpManager UI. ## OpManager Configuration #### **Configure Audit and Access logs** - Go to **Settings → General Settings → Integrations → SIEM (UDP/Syslog) - Configuration**. - Provide the **SIEM Application Name** as **'IBM QRadar'**. - Specify the **IP address** of the machine where IBM QRadar is hosted. - Enter the **port number** as **514** (default syslog port for IBM QRadar). - Select **Send Access logs** or choose **Audit modules** from the dropdown. You can also select both together based on your requirements. - Click on **Save.** ![OpManager -IBM](https://www.manageengine.com/network-monitoring/help/images/ibm-4.png) #### **Associate a Notification Profile** Follow the steps below to configure notification profile for IBM QRadar - Go to **Settings → Notification Profile** and click **Add**. - Select **SIEM**, then choose **SIEM (UDP/Syslog)**. - Enter the required parameters, including Format, Severity, Facility, Description, and relevant Variables. - If required, enable structured message and provide the inputs in the required fields. - Click on **Test Action** to verify the profile configuration. ![OpManager -IBM](https://www.manageengine.com/network-monitoring/help/images/ibm-5.png) - Learn more about configuring [criteria](https://www.manageengine.com/network-monitoring/help/configuring-notifications.html#criteria-notifications), [devices](https://www.manageengine.com/network-monitoring/help/configuring-notifications.html#select-devices), and [time window](https://www.manageengine.com/network-monitoring/help/configuring-notifications.html#applying-time-window) in notification profiles [here](https://www.manageengine.com/network-monitoring/help/configuring-notifications.html?siem_integration_ibm). - Click on **Save**. ## Verifying the Integration After the integration, IBM QRadar recieves the events from OpManager. ![OpMAnager -IBM](https://www.manageengine.com/network-monitoring/help/images/ibm-6.png) [Know more about the integrations offered by OpManager](https://www.manageengine.com/za/network-monitoring/integration.html?siem_integration_ibm_qradar) [Know more about dynamic variables used in request body](https://www.manageengine.com/za/network-monitoring/help/workflow-variables.html?siem_integration_ibm_qradar)