IBM QRadar Offense Ingestion for Security Operations
Create Security Incidents automatically from IBM QRadar offenses.
Install Trend
View Install Data
| Date | Install Count | Change |
|---|---|---|
| 2026-09-09 | 0 | - |
| 134 days of no change | ||
| 2026-04-27 | 57 | -57 |
| 166 days of no change | ||
| 2025-11-11 | 56 | +1 |
| 48 days of no change | ||
| 2025-09-23 | 55 | +1 |
| 20 days of no change | ||
| 2025-09-02 | 54 | +1 |
| 50 days of no change | ||
| 2025-07-13 | 53 | +1 |
| 74 days of no change | ||
| 2025-04-29 | 52 | +1 |
| 22 days of no change | ||
| 2025-04-06 | 51 | +1 |
| 48 days of no change | ||
| 2025-02-16 | 50 | +1 |
| 18 days of no change | ||
| 2025-01-28 | 49 | +1 |
| 89 days of no change | ||
| 2024-10-30 | 48 | +1 |
About
IBM® QRadar® Security Information and Event Management (SIEM) helps security teams accurately detect and prioritize threats across the enterprise. It provides intelligent insights that enable teams to respond quickly to reduce the impact of incidents. The IBM QRadar Offense Ingestion integration allows you to automatically fetch IBM QRadar offenses, convert them into security incidents, and enable automated response actions.
Key Features
This integration includes the following key features:
- Discovery of IBM QRadar offenses that are candidates for security incidents and automate the creation of security incidents.
- Mapping of offense, event, and flow fields to security incident fields.
- Aggregating similar offenses to existing open security incidents instead of creating duplicate security incidents.
- Validate your mapping with a preview of the offense field values in a security incident.
- Automatic offense status update for SIR incident creation and closure.
- Set up scheduled ingestions of offenses to create security incidents periodically.
- Fetch recent events or flows associated with an offense.
- Track key updates to offenses periodically.