QRadar Rule Manager - Enhanced is an extended version of the QRadar-Rule-Manager tool, designed to manage, import/export, and modify rules in IBM QRadar SIEM. This tool supports integration with GitHub and GitLab for easier rule storage and sharing.
- Python 3.8 or later
- Windows operating system
- Clone the repository
git clone https://github.com/YOUR_GITHUB_USERNAME/QRadar-Rule-Manager-Enhanced.git cd QRadar-Rule-Manager-Enhanced - Install dependencies
pip install -r requirements.txt
- Run the application
python code.py
-
Connect to QRadar
- Enter the QRadar URL.
- Enter the Security Token for authentication.
- Click "Get Rules" to fetch the existing rules list.
-
Import/Export Rules
- Select the rule(s) to export and click "Export".
- To import rules, select a
.zipfile and click "Import".
-
Manage Rule States
- Select a rule from the list.
- Click "Enable" to activate the rule.
- Click "Disable" to deactivate the rule.
- Click "Delete" to remove the rule from QRadar.
-
GitHub/GitLab Integration
- Provide your GitHub/GitLab token for authentication.
- Upload or download rules directly from the repository.
- This tool requires API access to QRadar.
- When using GitHub/GitLab, ensure your token has the necessary read/write permissions.
Special thanks to Mr.Koifman, the author of QRadar-Rule-Manager, for allowing the public release of these enhancements. The original tool serves as a crucial foundation for expanding and improving functionalities for managing QRadar SIEM.
For contributions or feedback, please open an issue or create a pull request on this repository.