SSBRUQ_51.0.0 - Documentation Index
Table of Contents
Welcome
IBM Security QRadar SOAR Platform documentation and resources
Release Notes
What's new in 51.0.10.x
What's new in 51.0.10.0
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.10.1
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.10.2
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.9.x
What's new in 51.0.9.0
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.9.1
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.9.2
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.8.x
What's new in 51.0.8.0
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.8.1
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.8.2
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.7.x
What's new in 51.0.7.0
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.7.1
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.7.2
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.6.x
What's new in 51.0.6.0
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.6.1
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.6.2
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.5.x
What's new in 51.0.5.0
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.5.1
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.5.2
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.4.x
What's new in 51.0.4.0
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.4.1
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.4.2
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.3.x
What's new in 51.0.3.0
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.3.1
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.3.2
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.2.x
What's new in 51.0.2.0
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.2.1
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.2.2
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.1.x
What's new in 51.0.1.0
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.1.1
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.1.2
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.0.x
What's new in 51.0.0.0
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.0.1
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
What's new in 51.0.0.2
Features and enhancements
Privacy updates
Upgrade notes
Corrected issues
Known issues
Getting started with the SOAR Platform
Overview of the IBM Security QRadar SOAR
Incident management team
SOAR system administrator
Playbook designer and custom playbooks
App developer for SOAR
SOAR site planner
SOAR Platform documentation and communities
Site manager (on-premises only)
Installing the SOAR Platform
Virtual appliance installation introduction
Obtaining the SOAR software
SOAR Platform virtual appliance installation prerequisites
Virtual appliance installation overview
SOAR Platform Managed Security Service Providers add-on
Getting started with the installation
Deploying the SOAR appliance
Importing the SOAR license
Connection and updates
Updating the SOAR appliance software
Setting the time zone
Secure Socket Layer certificate
Creating the certificate request
Importing the signed certificate
Updating the certificate
Accounts and extra configuration
Default users and groups
Creating the initial user account
Configuring LDAP authentication
Configuring SAML authentication
Changed in 51.0.1.0 Configuring two-factor authentication
Adding user accounts
Password and API expiration
Importing untrusted certificates
Changing the temporary directory
Configuring the base URL
Network configuration settings
New in 51.0.4.0 Sanitizing values in incident reports
Changed in 51.0.9.0 Configuring trusted IP addresses using resutil
New in 51.0.9.1 Removing old PostgreSQL packages
Configuring a proxy for threat feeds
Log file configuration
Email notification configuration
Email security – defanging URLs
Changed in 51.0.9.0 Changing secure ciphers
Managing SOAR services
SOAR Platform KeyVaults and secrets
Storage format, location and key
KeyVault configuration options
Encrypting the KeyVault password
SOAR KeyVault backup
Changed in 51.0.6.0 Managing KeyVault secrets
Configuring maximum image size
SOAR audit logs
Configuring syslog for audit logs
Configuring audit logging
Audit log messages
Sending audit data to Splunk Cloud
Monitoring with SNMP
Installing SNMP on the SOAR Platform
Installing SNMP on the monitoring server
Sample SNMP commands
Configuring SNMP V3 traps
Backup and restore
Backup using soarSystemBackup
Backup using resSystemBackup
Restoring from a soarSystemBackup file
Restoring from a resSystemBackup file
Upgrading
Installing optional packages
Introduction to run file installation
SOAR Platform Managed Security Service Providers add-on
SOAR Platform .run file installation prerequisites
Deploying the SOAR Platform .run file
Importing the SOAR Platform license
Setting the time zone
Secure Socket Layer certificate
Creating the certificate request
Importing the signed certificate
Updating the certificate
Accounts and extra configuration
User accounts and groups
Creating the initial user account
Configuring LDAP authentication
Configuring SAML authentication
Changed in 51.0.1.0 Configuring two-factor authentication
Adding user accounts
Password and API expiration
Importing untrusted certificates
Changing the temporary directory
Configuring the base URL
Network configuration settings
New in 51.0.4.0 Sanitizing values in incident reports
Changed in 51.0.9.0 Configuring trusted IP addresses using resutil
New in 51.0.9.1 Removing old PostgreSQL packages
Configuring a proxy for threat feeds
Log file configuration
Email notification configuration
Email security – defanging URLs
Changed in 51.0.9.0 Changing secure ciphers
Managing SOAR services
SOAR Platform KeyVaults and secrets
Storage format, location and key
KeyVault configuration options
Encrypting the KeyVault password
SOAR KeyVault backup
Changed in 51.0.6.0 Managing KeyVault secrets
Configuring maximum image size
SOAR audit logs
Configuring syslog for audit logs
Configuring audit logging
Audit log messages
Sending audit data to Splunk Cloud
Backup and restore
Backup using soarSystemBackup
Backup using resSystemBackup
Restoring from a soarSystemBackup file
Restoring from a resSystemBackup file
Changed in 51.0.8.0 Upgrading the SOAR Platform
Overview of SOAR disaster recovery
SOAR disaster recovery prerequisites
Installing and setting up DR
Step 1: Installing
Step 2: Setting up
Step 3: Configuring postgres for SSL
Step 4: Creating Ansible inventory files
Step 5: Creating Ansible vault files
Configuring apps to work with DR
Configuring apps running on an App Host
Configuring apps running on an integration server
Running the actions
Enabling SOAR disaster recovery
Swapping the primary and secondary appliance
Optional: removing stale backups
Promoting the secondary appliance as the active SOAR appliance
Scenario: reverting to original appliance states
Disabling SOAR Disaster Recovery
Using the health monitor
Configuring the health monitor
Viewing status from the command line
Upgrading, known issues, and security considerations
Upgrading SOAR Disaster Recovery
Security considerations for Disaster Recovery
Known issues for SOAR Disaster Recovery
SOAR sizing guidelines introduction
Recommendations for workloads
SOAR platform utilization guidelines
CPU utilization guidelines
SOAR platform memory guidelines
SOAR platform Disk I/O
SOAR platform disk space guidelines
SOAR sizing guidelines conclusion
Tracking license usage of stand-alone IBM Containerized Software
What's New
Preparing for installation
Installing License Service for stand-alone software
Automatic installation using Operator Lifecycle Manager (OLM)
Manual installation on OpenShift Container Platform (OCP) version 4.6 or later
Manual installation without Operator Lifecycle Manager (OLM)
Manual installation on Kubernetes from scratch with kubectl
Offline installation
Uninstalling
Backup and upgrade
Configuration
Hyperthreading
Audit snapshot
Reported metrics
Enabling optional features
Retrieving license usage data
API authentication
License Service API token
Service account token
APIs
Obtaining a status page
Swagger API schema
Tracking license usage in multicluster environment
Troubleshooting
IBM Security QRadar SOAR and data encryption
Configuring Openshift routes for accessing SOAR services
SOAR system administrator
SOAR administration and organization settings
Managing SOAR Platform users
Managing SOAR Platform groups
Managing SOAR Platform roles
SOAR platform workspaces
Timesframes and approved IP addresses and network
SOAR platform organization settings
Changed in 51.0.9.0 Configuring an inbound email connection
New in 51.0.9.0 Migrating an OAuth EWS connection to MS graph
Enabling or disabling threat sources
SOAR Platform notifications
Changed in 51.0.10.0 Creating a notification
Using substitution values
Changed in 51.0.10.1 Managing SOAR apps
Before you install an app
Download apps from App Exchange
Upgrading an app
Installing an app
Configuring an app
Protected secret for sensitive data
Advanced configuration settings
Third-party credential managers
Configuring apps for HashiCorp Vault
Cyberark Central Credential Provider
Managing App Hosts
Apps and App Host logs
Creating and editing SOAR wiki pages
LDAP authentication for SOAR
Preparing for LDAP authentication
Enabling LDAP authentication
Managing LDAP users in groups
Error handling and notifications
Changed in 51.0.7.0 SOAR system settings configuration
New in 51.0.9.0 Configuring trusted IP addresses
Playbook designer
Playbook design basic concepts
Playbooks planning overview
SOAR playbook toolkit
Incident layouts
Rules
Scripts
Scope of scripts
Python 2 and Python 3 differences
Writing scripts for playbooks
Artifact operations in playbooks
Attachment operations in scripts
Email message operations
Fields operations for scripts
Groups operations in scripts
Helper operations for scripts
Incident operations for scripts
Log operations for scripts
Milestone operations for scripts
Note operations for scripts
Playbook operations for scripts
Principal operations and scripts
Query builder operations
Row operations and scripts
Rule operations and scripts
Task operations and scripts
Testing scripts
Considerations for writing scripts
Associating email messages with incidents
Example script for email parsing
Adding values to multi-select lists
Writing scripts for different languages
Workflows
Workflow palette and tools
Designing a workflow
Creating a workflow
Using timer events
Using functions and associated scripts
Using conditions and scripts
Workflows and transaction processing
Functions
Destinations
Phases and tasks
Incident types
Breach settings
Artifact types
Build and manage playbooks
Creating a playbook that is activated automatically
Creating a playbook that is activated manually
Playbook activation form
Creating a sub-playbook
Outputs
Playbook result value
Setting conditions that activate a playbook
Building the playbook
Tasks
Changed in 51.0.7.0 Connectors and functions
New in 51.0.6.0 Creating custom connector functions for playbooks
Changed in 51.0.6.0 Creating connector functions by importing OpenAPI 3.x spec files
Changed in 51.0.6.0 Editing a connector
Deleting a connector
Associating connectors with an App Host
Adding functions to playbooks
Downloading connector log files
Building playbook scripts
Input scripts
Sub-playbooks
Decision points
Wait points
Condition points
Script builder
End points
Enabling a playbook
Duplicate playbooks and sub-playbooks
Duplicating playbooks
Duplicating sub-playbooks
Canceling a playbook
Canceling a playbook automatically
Changed in 51.0.6.0 Exporting and importing playbooks
Converting rules to playbooks
Changed in 51.0.9.0 Viewing playbook instances
Changed in 51.0.10.0 Viewing playbook change logs
Example of a playbook
Incident management team
Introduction to incident response
Getting started in incident response
Changed in 51.0.5.0 Reviewing the list of incidents
Creating an incident
Managing your incidents
Triaging inbound email
Reports and analysis
Creating custom incident graphs
New in 51.0.7.0 Carbon charts replace legacy charts
Navigation and search
SOAR Apps and App Host
Introduction to SOAR App Host
App Host terminology and concepts
SOAR App Host architecture
SOAR Platform apps
App Host installation overview
App Host prerequisites
App Host network configuration
Install the App Host
Changed in 51.0.0.0 Installing the virtual appliance
Installing optional packages
Virtual appliance in an air gap environment
Stand-alone software
Standalone software in an air gap environment
Create an App Host pairing
Create the App Hosts
Configuring proxy authentication
New in 51.0.0.0 Migrating App Hosts between appliances
App Host disaster recovery
App Hosts and a private repository
Configuring a private repository
Mirroring quay.io repository
Upgrading the App Host
Uninstalling the App Host
Troubleshooting App Host problems
Checking the Kubernetes container
Checking the App Host and containers
App is stuck 'Deploying...' or in an Error state
SSL: CERTIFICATE_VERIFY_FAILED error for an app
App does not work after its rules start
Checking connection errors
Connection error when certificate is refreshed
App Host does not upgrade
App Host version is unknown
Unable to select the App Host
Checking the logs
Introduction
What is an app?
SDK
REST API
Development overview
Developer resources
Development environment
SOAR playbook components
Function input field considerations
Function post-process script considerations
Creating the app
Coding considerations
Data flow
Error handling
Logging
Data results
Linking to 3rd party app objects
Rich text and temporary files
Avoid using self.
Functions in componentsdir
Testing the app
Configuration settings
Testing the app
Packaging your app
Validating your app
Publishing your app
Converting an extension into an app
Updating apps to Python 3.9
Introduction
Architecture
Standard Deployment
SOAR platform with MSSP add-on
On-premises SOAR platform
Supported app types
Prerequisites
Integration server
SOAR platform
Network configuration
Installation on a Linux system
Downloading Resilient Circuits (offline only)
Installing Resilient Circuits
Configuring Resilient Circuits for restart
Installing Resilient circuits
Using encrypted keys (optional)
Keyring utility
Free Desktop Secret Service
Keyrings cryptfile
Windows Credential Locker
Configuration
Configuring proxy authentication
Editing the configuration file
Monitoring the config file for changes
Configuring servers in an MSSP deployment
Updating your environment
Configuring SSL Certificates to use with the SOAR Platform
App packages
Installing an app
Upgrading an app
Deploying an app
Troubleshooting
Support
SOAR for MSSPs
Architecture and deployment overview
Creating and managing MSSP-specific organizations
Creating a configuration organization
Creating a global dashboard
Creating a child organization
Setting up users and permissions
Creating the administrator account
Changed in 51.0.1.0 Creating MSSP users
Creating API key accounts
Changed in 51.0.1.0 Creating groups and roles
Managing user accounts
Adding MSSP users to an organization
Deactivating MSSP users
Deleting MSSP users
Managing apps and App Hosts
Propagating configuration changes
Configuring inbound email connections
Administration in child and dashboard organizations
SOAR MSSP architecture and overview
Accessing the global dashboard
Working in a child organization
IBM Security QRadar SOAR tutorials
Tutorial: Creating custom connectors
Lesson 1: Creating a custom connector
Lesson 2: Configure a playbook to use the connector function
Lesson 3: Running the playbook with the connector function
Tutorial: Creating custom graphs over time
Lesson 1: Creating a basic graph
Lesson 2: Adding more fields
Tutorial: Processing inbound email
Lesson 1: Creating an email connection
Lesson 2: Assigning email permissions
Lesson 3: Configuring a sample email script
Lesson 4: Creating a rule to process the script