Question & Answer
The purpose of the technical note is to provide a FAQ for administrators using the X-Force Exchange (XFE) right-click context menu plug-in with IBM Security QRadar. This document covers installation and usage.
- What is the IBM X-Force Exchange right-click context menu plug-in?
- Where is the IBM X-Force Exchange right-click context menu plug-in located in the QRadar user interface?
- Using the IBM X-Force Exchange right-click context menu plug-in for the first time
- How do I install the IBM X-Force Exchange right-click context menu plug-in?
- Where can I find more information?
IBM X-Force Exchange (XFE) is a threat intelligence sharing platform for security analysts, network security specialists, Security operations center (SOC) teams. The X-Force Exchange allows users to search for IPs, URLs, CVEs, web applications and also contribute either public or private information to track data in collections when researching security issues.
The IBM X-Force Exchange right-click context menu plug-in allows users to easily conduct right-click menu lookups against X-Force Exchange for IP addresses found in the QRadar user interface, and URLs from the Log Activity tab; allowing you to easily research the information found in X-Force Reports against date found in searches, offenses, and rules.
Figure 1: A screen capture of X-Force Exchange (click to enlarge image).
Where is the IBM X-Force Exchange right-click context menu plug-in located in the QRadar user interface?
The right-click options is found under the right click menu. There are two right-click menus depending on where you are in QRadar:
- The IP Addresses on the Offenses tab and Event Details screens, as well as all URL fields, have the right-click menu as: Plugin Options > X-Force Exchange Lookup.
- The IP Addresses on the Log Activity and Network Activity tabs have the right-click menu as: More Options > Plugin Options > X-Force Exchange Lookup.
The first time the X-Force Exchange Lookup is used, a pop-up window opens for the X-Force Exchange website. To complete an X-Force Exchange Lookup, the user must log in using an IBM ID.
After the initial log in to the IBM X-Force Exchange site, the browser window can be closed. As long as the session is still valid the QRadar user can complete lookups without having to re-authenticate to the X-Force Exchange website.
The response to the lookup from the QRadar user interface is a pop-up window showing the X-Force Exchange portal's information on the IP or URL selected in the lookup. The report will include a category, a confidence rating in the case of IP, and other information related to the IP address or URL.
A copy of the current X-Force Report can also be added to a Collection. A Collection is a repository used to store X-Force reports, and any relevant uploads you may have.
This information can be shared with your group or any other X-Force Exchange users you choose.
As of 7.3 the IBM X-Force Exchange right-click context menu plug-in is already preinstalled.
QRadar Consoles prior to QRadar 7.3 can install theIBM X-Force Exchange right-click context menu plug-in, as long they are at QRadar 7.2.3 (220.127.116.116253) or later.
To install the IBM X-Force Exchange right-click context menu plug-in, administrators must download and manually install the plug-in on the QRadar Console.
Before you begin
This procedure requires a Web Server restart from the Admin tab to load the plug-in after the RPM is installed. Restarting the web server logs out all QRadar users, so it is advised that administrators install this plug-in during scheduled maintenance.
- Download the IBM X-Force Exchange right-click context menu plug-in from IBM Fix Central: https://ibm.biz/BdX4BW (IBM shortened URL)
- Copy the RPM file to the QRadar Console.
- To install the plug-in, type the following command:
rpm -Uvh 7.2.0-QRADAR-RightClick-XFE-7.2.1-1426795712.x86_64.rpm
- Log in to QRadar Console as an admin user.
- Click the Admin tab.
- Select Advanced > Restart Web Server.
After the web server restart completes, the IBM X-Force Exchange right-click context menu plug-in is enabled for IP addresses throughout the QRadar user interface and for URL fields in the Log Activity tab.
If you have additional questions or some of this content is not clear, you can see the following resources:
- X-Force Exchange information
Where do you find more information?
Was this topic helpful?
16 June 2018