DocumentationRelease Notes
Log In
Documentation

IBM QRadar Connector

Configure IBM QRadar connector

IBM QRadar® is a security intelligence platform that provides a unified architecture for integrating security information and event management solutions. Create a QRadar connector to send selected event data in QRadar LEEF format.

  1. In BeyondInsight, go to Configuration > General > Connectors.
  2. From the Connectors pane, click Create New Connector.
  3. Enter a name for the connector.
  4. Select IBM QRadar from the Connector Type list.
  5. Click Create Connector.
  6. Leave Active (yes) enabled.
  7. Provide the required details for the IBM QRadar server:
    • Select the protocol from the Available Output Pipelines list: TCP, TCP-SSL, or UDP.
    • Enter Host Name and Port.
  8. Select the formatter from the dropdown list.
    • LEEF Format V1 uses a static identifier per event type.
    • LEEF Format V2 uses a unique event identifier generated per event type.
  9. If you selected LEEF Format V2 in the previous step, select the Facility from the dropdown list. This option is not available for LEEF Format V1.
  10. Expand Event Filters, and then select the events that you want to forward.
  11. Click Test Connector to send a test event message.
  12. Click Create Connector.

ℹ️

Note

If an event is received from Password Safe Cloud, a Resource Zone can now be associated with any connector that sends data using syslog. If selected, Password Safe Cloud proxies the syslog data through the Resource Brokers associated with that Resource Zone.

ℹ️

Note

Unique identifiers are preset, but can be customized if desired, using a setting in the BeyondInsight database table:

dbo.ConfigurationItem BeyondTrust.Configuration.ProductConfigurations.LeefFormatterConfig

Password Safe QRadar fields

FieldValue TypeDescription
CategoryStringSystem/Change
EventNameStringSystem / Functional / Managed / Change
LogIDIntegerPMMLogSystem/PMMLogChange table reference ID
LogTimeDateTimeTime of event
DetailsStringMiscellaneous additional information
UserNameStringUsername associated with the event
RoleUsedStringRole used
ObjectTypeIDIntegerObject Type reference ID
ObjectTypeStringObject Type (e.g. Functional Account, System, Session)
ObjectIDIntegerObject reference ID
OperationStringOperation (e.g.. Add, Update, Approve)
FailedBooleanTrue / False
TargetStringDescribes the asset acted upon (e.g. Asset:testasset Account:testaccount)
UserIDIntegerUser ID associated with the event
IPAddressStringIP address of the system
ManagedAccountIDIntegerManaged Account reference ID
FunctionalAccountIDIntegerFunctional Account reference ID
ManagedSystemIDIntegerManaged System reference ID
ChangeDtDateTimeTime of password change
ChangeReasonCdStringReason for password change:
A = Password change by API
F = Forced password reset
M = Password reset on mismatch
N = Manual password entry for new account
O = Initial onboarding via smart rule
P = Change by EPM agent
R = Post release password reset
S = Scheduled password change
T = Ticket approval release password reset
U = Manual password entry
V = Approval release password reset
X = Synced password with primary
Y = Un-synced password from primary
Z = Forced password sync with primary
ResultStringPassword change result: (S)uccess or (F)ailed
CommentStringMiscellaneous additional information
ReleaseIDIntegerPassword release reference ID
RequestIDIntegerRequest reference ID
WorkgroupIDIntegerWorkgroup reference ID
WorkgroupStringWorkgroup name
AccountNameStringAccount name
NextChangeDateDateTimeNext scheduled change date
ElevationCommandStringElevation command used, if any

©2003-2025 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.