<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Forwarding Specific Alert Severities to QRadar in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Forwarding-Specific-Alert-Severities-to-QRadar/m-p/249541#M10586</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;As part of integrating Harmony EDR solution with our SIEM platform (QRadar), I would like to confirm whether it is possible to forward only alerts with Medium, High, and Critical severities to QRadar.&lt;/P&gt;&lt;P&gt;If this is feasible, is it with the forwarding through a Syslog server or directly to QRadar via an API call?&lt;/P&gt;&lt;P&gt;Please note that the Harmony EDR instance is deployed in SaaS mode.&lt;/P&gt;&lt;P&gt;Thank you in advance for your assistance&lt;/P&gt;</description>
    <pubDate>Wed, 21 May 2025 20:14:44 GMT</pubDate>
    <dc:creator>Fares-Ayed</dc:creator>
    <dc:date>2025-05-21T20:14:44Z</dc:date>
    <item>
      <title>Forwarding Specific Alert Severities to QRadar</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Forwarding-Specific-Alert-Severities-to-QRadar/m-p/249541#M10586</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;As part of integrating Harmony EDR solution with our SIEM platform (QRadar), I would like to confirm whether it is possible to forward only alerts with Medium, High, and Critical severities to QRadar.&lt;/P&gt;&lt;P&gt;If this is feasible, is it with the forwarding through a Syslog server or directly to QRadar via an API call?&lt;/P&gt;&lt;P&gt;Please note that the Harmony EDR instance is deployed in SaaS mode.&lt;/P&gt;&lt;P&gt;Thank you in advance for your assistance&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2025 20:14:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Forwarding-Specific-Alert-Severities-to-QRadar/m-p/249541#M10586</guid>
      <dc:creator>Fares-Ayed</dc:creator>
      <dc:date>2025-05-21T20:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarding Specific Alert Severities to QRadar</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Forwarding-Specific-Alert-Severities-to-QRadar/m-p/249969#M10587</link>
      <description>&lt;P&gt;Should be possible, yes:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Portal-Admin-Guide/Content/Topics-Infinity-Portal/Event-Forwarding.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Portal-Admin-Guide/Content/Topics-Infinity-Portal/Event-Forwarding.htm&lt;/A&gt;&lt;BR /&gt;Note this requires a specific license; please consult with your local Check Point office.&lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2025 22:12:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Forwarding-Specific-Alert-Severities-to-QRadar/m-p/249969#M10587</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-05-27T22:12:54Z</dc:date>
    </item>
  </channel>
</rss>

