IBM Support

QRadar: How to export saved searches results using QRadar API

How To


Summary

To export the events from a saved search in any of the supported formats: JSON, CSV, XML, or tabular text. You have to get first the Search ID (search_id) and to obtain the search_id, you need the saved_search_id. This article contains the steps by step to get this information.

Document Location

Worldwide

[{"Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000cwtEAAQ","label":"Log Activity"}],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions","Type":"MASTER"}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
25 April 2024

UID

ibm16540268