To send events to QRadar from your VMware AppDefense
system, you must create a new API key on your VMware AppDefense system.
Before you begin
Ensure that you have access to the Integrations settings in the VMware AppDefense
user interface so that you can generate the Endpoint URL and API Key that are required to configure
a log source in QRadar. You
must have the correct user permissions for the VMware AppDefense user interface to complete the
following procedure:
Procedure
-
Log in to your VMware AppDefense user interface.
-
From the navigation menu, click the icon to the right of your user name, and then select
Integrations.
-
Click PROVISION NEW API KEY.
-
In the Integration Name field, type a name for your integration.
-
Select an integration from the Integration Type list.
-
Click PROVISION, and then record and save the following information from
the message in the window that opens. You need this information when you configure a log source in
QRadar:
- EndPoint URL
- API Key - This is the Authentication Token
parameter value when you configure a log source in QRadar.
Note: If you click OK or close the window, the information in the message
can't be recovered.