Configuring VMware AppDefense to communicate with QRadar

To send events to QRadar from your VMware AppDefense system, you must create a new API key on your VMware AppDefense system.

Before you begin

Ensure that you have access to the Integrations settings in the VMware AppDefense user interface so that you can generate the Endpoint URL and API Key that are required to configure a log source in QRadar. You must have the correct user permissions for the VMware AppDefense user interface to complete the following procedure:

Procedure

  1. Log in to your VMware AppDefense user interface.
  2. From the navigation menu, click the icon to the right of your user name, and then select Integrations.
  3. Click PROVISION NEW API KEY.
  4. In the Integration Name field, type a name for your integration.
  5. Select an integration from the Integration Type list.
  6. Click PROVISION, and then record and save the following information from the message in the window that opens. You need this information when you configure a log source in QRadar:
    • EndPoint URL
    • API Key - This is the Authentication Token parameter value when you configure a log source in QRadar.
    Note: If you click OK or close the window, the information in the message can't be recovered.