Skip to content

About

No description, website, or topics provided.

Resources

Stars

4 stars

Watchers

1 watching

Forks

Latest commit

 

History

4 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 

Repository files navigation

QRadar Rule Manager - Enhanced

Introduction

QRadar Rule Manager - Enhanced is an extended version of the QRadar-Rule-Manager tool, designed to manage, import/export, and modify rules in IBM QRadar SIEM. This tool supports integration with GitHub and GitLab for easier rule storage and sharing.

Installation

System Requirements

  • Python 3.8 or later
  • Windows operating system

Setup Environment

  1. Clone the repository
    git clone https://github.com/YOUR_GITHUB_USERNAME/QRadar-Rule-Manager-Enhanced.git
    cd QRadar-Rule-Manager-Enhanced
  2. Install dependencies
    pip install -r requirements.txt
  3. Run the application
    python code.py

Usage Guide

  1. Connect to QRadar

    • Enter the QRadar URL.
    • Enter the Security Token for authentication.
    • Click "Get Rules" to fetch the existing rules list.
  2. Import/Export Rules

    • Select the rule(s) to export and click "Export".
    • To import rules, select a .zip file and click "Import".
  3. Manage Rule States

    • Select a rule from the list.
    • Click "Enable" to activate the rule.
    • Click "Disable" to deactivate the rule.
    • Click "Delete" to remove the rule from QRadar.
  4. GitHub/GitLab Integration

    • Provide your GitHub/GitLab token for authentication.
    • Upload or download rules directly from the repository.

Notes

  • This tool requires API access to QRadar.
  • When using GitHub/GitLab, ensure your token has the necessary read/write permissions.

Acknowledgment

Special thanks to Mr.Koifman, the author of QRadar-Rule-Manager, for allowing the public release of these enhancements. The original tool serves as a crucial foundation for expanding and improving functionalities for managing QRadar SIEM.


For contributions or feedback, please open an issue or create a pull request on this repository.

About

No description, website, or topics provided.

Resources

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages