Skip to main content
Connect your IBM QRadar SIEM so Myrmex can query events and flows, review offenses, and enrich investigations. Myrmex reaches QRadar over its REST API (HTTPS) through a Collector on your network. Every search runs live, on demand — Myrmex returns only what you ask for at that moment and copies or stores nothing from QRadar on its side. Credentials are resolved on your side and never pass through the model.

What Myrmex Can Do

Query events & flows

Run searches against QRadar events and flows to answer investigation questions — read-only.

Review offenses

List and inspect offenses to understand what QRadar has already correlated.

Enrich investigations

Pull live context on hosts, users, and indicators to support alert triage.

Live, nothing stored

Myrmex queries QRadar in real time and returns only the result you asked for — no copy is kept on the Myrmex side.

Before You Start

  • A Collector that can reach the QRadar console over HTTPS (default port 443). See Collector mode.
  • A QRadar user role and security profile that can read events, flows, and offenses (read-only is enough for analysis).
  • An authorized service token — you create this in Step 1.

Step 1 — Create the Credential in QRadar

1

Open Authorized Services

In the QRadar console, go to Admin → User Management → Authorized Services.
2

Add an authorized service

Click Add Authorized Service, give it a name, and assign a User Role and Security Profile that scope what the token can read.
3

Generate and copy the token

Set an expiry (or no expiry), create the service, and copy the generated token. QRadar expects this token in the SEC HTTP header, which Myrmex sends for you.
Start with a read-only role and security profile. Grant broader access only if you later want the agents to act, not just analyze.

Step 2 — Add the Integration in Myrmex

From the Directory, choose Add Integration → IBM QRadar, then fill in:

Connect

Click Connect to validate the REST connection and finish. QRadar then appears under Environment → Integrations, and you can ask about it in the Workspace or through the Integration Specialist agent.
Prefer HTTPS with a valid certificate on the console. If your API is exposed on a non-default port, include it in the URL field.