03-10-2016 10:35 AM
Hi team,
What's the current status of ISE and IBM Qradar Integration? Can IBM Qradar integrate via pxGrid to get contextual information and tell ISE to quarantine certain endpoints? Do we have any configuration documentation available?http://www.cisco.com/c/en/us/support/security/identity-services-engine/products-implementation-design-guides-list.html
Thanks in advance,
Oriol
Solved! Go to Solution.
06-26-2017 03:07 PM
Hi,
No, this is not possible today with Qradar, currently there is a Qradar app being developed that will have Adaptive Network Control (ANC) functionality. I will let you know when this becomes available.
Thanks,
John
03-10-2016 12:22 PM
This is still under discussion driven by Doug Hurd (dohurd@cisco.com) and his team
Thanks
Imran
02-22-2017 03:41 AM
Any updates on this topic?
Thanks
02-22-2017 07:06 AM
Hey Tiago,
QRadar is still via ISE syslogs, if you have customers or partners who are in interested in pxGrid with Qradar can you send me a list.
Thanks,
John
06-26-2017 01:30 PM
I work for Cisco partner - one our customer is very interesting in integration ISE and QRadar - both products is now used in his network. He would like to use his CIEM system (or QRadar) to be able to initialize blocking or quarantining some host (with security risk behaviour). I check the ISE REST API and it seems to me it could be quite easy to put the endpoint ID (MAC address) to some Endpoint Group (like Security Incident) and setup general authorization exception, which set apropriate result for the endpoint (SGT, VLAN DACL..).
But I will need also to initialize some endpoint reauthentication - or CoA ??. Is it possible to initialize this by ISE REST API - in case not, is there any other way how to manage this?
Thank you
06-26-2017 03:07 PM
Hi,
No, this is not possible today with Qradar, currently there is a Qradar app being developed that will have Adaptive Network Control (ANC) functionality. I will let you know when this becomes available.
Thanks,
John
11-22-2017 02:49 AM
Dear John,
Is there any update about Qradar integration with ISE via PxGrid? If so, is there Any official documents, links that we can refer to?
Regards,
Georges
11-22-2017 03:57 AM
Hey Georges,
The Qradar app is still under development, will follow-up with you when this has been completed.
Thanks,
John
04-19-2018 12:05 AM
Hi John,
Is there any update on IBM Qradar app development? We want to integrate ISE 2.4 with IBM Qradar SIEM 7.2.8 & 7.3 version.
Kindly let us know any document available for same.
04-19-2018 07:22 AM
Hey Dnyaneshwar,
The Cisco ISE pxGrid App for QRadar is in IBM"s validation process phase, the How-to document will be available as well.
The Cisco ISE pxGrid APP for QRadar is certified on QRadar 7.2.8 patch 9.
Thanks,
John
04-19-2018 08:39 AM
Thx for reply John.
When do you think it will be available?
Sent from my iPhone
05-04-2018 07:05 AM
Just released on May 1.
Document can be found on
https://exchange.xforce.ibmcloud.com/hub/extension/6091fd93042043212fd2494fe97ff5b7
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide