- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Palo Alto Networks and IBM have partnered to deliver advanced security reporting and analytics to the the widely used IBM® QRadar® SIEM. Integrate QRadar seamlessly with the Palo Alto Networks platform to streamline operations and improves s
...
I am trying to fetch a report from qradar but could not find any command for that I also tried fetching it through AQL but there I am only getting 50 events, is there any way we can get the report.
Any plan to publish new version of app. The current one is deprecated and cannot be installed
https://exchange.xforce.ibmcloud.com/hub/extension/Palo%20Alto%20Networks:Palo%20Alto%20Networks%20App%20for%20QRadar
As of Palo Alto Networks App for QRadar version 1.1.0, we have exclusively switched to LEEF log format support. Below are the details on how to install our standard log extension. This will overwrite the custom properties to use standard log format.
...
Confirm you are receiving LEEF log format in QRadar, navigate to the “Log Activity” tab of QRadar and create an advanced search:
SELECT UTF8(payload) FROM event...