Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Fares-Ayed
Explorer

Forwarding Specific Alert Severities to QRadar

Hello,

As part of integrating Harmony EDR solution with our SIEM platform (QRadar), I would like to confirm whether it is possible to forward only alerts with Medium, High, and Critical severities to QRadar.

If this is feasible, is it with the forwarding through a Syslog server or directly to QRadar via an API call?

Please note that the Harmony EDR instance is deployed in SaaS mode.

Thank you in advance for your assistance

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

Should be possible, yes: https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Portal-Admin-Guide/C...
Note this requires a specific license; please consult with your local Check Point office.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events