Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Import from multiple QRadar instances #46

Open
schovol opened this issue Jan 31, 2020 · 2 comments
Open

Import from multiple QRadar instances #46

schovol opened this issue Jan 31, 2020 · 2 comments

Comments

@schovol
Copy link

schovol commented Jan 31, 2020

As a MSSP we need to import offenses from multiple customer QRadar instances. I am missing a filed for distinguishing between different source in the alerts list. How about adding a tag or setting the source apppropriately?

@aymansabri
Copy link

I have the same question , I want to connect multiple QRadar client to thehive4, each QRadar IP linked to an organisation.

How can we do that with just one Synapse instance running ?

@ihebski
Copy link

ihebski commented Jul 28, 2023

hello @schovol under QRadar2Alert.py you can add a specific tag in line 104 tags = ['QRadar', 'Offense', 'Synapse'] that specify the QR instance name or ID per running Synapse.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants