logo

NJP

IBM QRadar Offense Ingestion for Security Operations

IBM QRadar Offense Ingestion for Security Operations

by Service-now.com

Create Security Incidents automatically from IBM QRadar offenses.

0 installs 0 reviews v10.7.4 Scoped Application Free (integration tables[13] not counted) 13 tables
Developer Instance Sub-Production

Install Trend

First tracked: 2024-10-30 Latest: 2026-09-09 (0 installs)
View Install Data
Date Install Count Change
2026-09-09 0 -
134 days of no change
2026-04-27 57 -57
166 days of no change
2025-11-11 56 +1
48 days of no change
2025-09-23 55 +1
20 days of no change
2025-09-02 54 +1
50 days of no change
2025-07-13 53 +1
74 days of no change
2025-04-29 52 +1
22 days of no change
2025-04-06 51 +1
48 days of no change
2025-02-16 50 +1
18 days of no change
2025-01-28 49 +1
89 days of no change
2024-10-30 48 +1

About

IBM® QRadar® Security Information and Event Management (SIEM) helps security teams accurately detect and prioritize threats across the enterprise. It provides intelligent insights that enable teams to respond quickly to reduce the impact of incidents. The IBM QRadar Offense Ingestion integration allows you to automatically fetch IBM QRadar offenses, convert them into security incidents, and enable automated response actions.

Key Features

This integration includes the following key features:

- Discovery of IBM QRadar offenses that are candidates for security incidents and automate the creation of security incidents.
- Mapping of offense, event, and flow fields to security incident fields.
- Aggregating similar offenses to existing open security incidents instead of creating duplicate security incidents.
- Validate your mapping with a preview of the offense field values in a security incident.
- Automatic offense status update for SIR incident creation and closure.
- Set up scheduled ingestions of offenses to create security incidents periodically.
- Fetch recent events or flows associated with an offense.
- Track key updates to offenses periodically.

Version History (10)
v10.7.4 2026-06-16 16:43:43
Fixed: Duplicate SIR creation issue for single offense in IBM Qradar. Cobalt Raven Non-Glide Query ACLs Directive.
v10.7.3 2026-04-09 15:25:28
Fixed: SIR creation issue in case of secure notes mapping. Preview Section so that Event Data is now displayed correctly.
v10.7.1 2026-03-12 16:13:23
New: Added support to fetch ADE Rules from IBM QRadar into Security Incident Response. Introduced strategies to present offense data without depen...
v10.6.1 2026-02-06 01:22:10
Fixed "Fetch Sample Data" functionality on the mapping screen for IBM QRadar SIEM Offense Ingestion.
v10.6.0 2026-01-20 15:04:23
New: Added support for fetching closed incidents from IBM QRadar into Security Incident Response.
v10.5.0 2025-12-11 13:41:56
New : Upgraded all dictionary-level read-only fields to Strict Read-Only to enhance security and prevent unauthorized changes.This update ensures ...
v10.4.22 2025-10-23 15:26:26
Fixed:  A duplicate record creation in the Polling table for the same offense. An issue with empty Integration Run column in QRadar tables. T...
v10.4.20 2025-10-16 15:10:59
Fixed:- Optimized the offense ingestion process to handle events efficiently. These enhancements reduce latency, improve throughput, and ensure fa...
v10.4.19 2025-09-10 12:06:25
Fixed: Optimized the offense ingestion process to handle events efficiently. These enhancements reduce latency, improve throughput, and ensure fas...
v10.4.14 2024-11-07 15:06:49
Fixed: Fixed an issue where QRadar profile gets stuck in running state when system is restarted or shut down.
ID: 47383796c7340010c20eb5a827c2606e · Published: Jun 2026 · Updated: Sep 09, 2026