VMRay QRadar InstallationandUserGuide1
VMRay QRadar InstallationandUserGuide1
VMRay-QRadar
App v1.0.0
1
VMRay-QRadar App v1.0.0
Table of contents
Overview 3
Prerequisites 3
Installation 3
2
VMRay-QRadar App v1.0.0
Overview
This document describes how to install and use the QRadar App for VMRay Analyzer. The
QRadar App for VMRay Analyzer integrates the QRadar Platform with VMRay Analyzer. The app
can be configured to receive events from VMRay. The analysis reports generated by VMRay are
received as events in QRadar and can be shown in the Dashboard created by the app.
Prerequisites
Verify that your environment meets the following requirements:
Installation
Perform the following steps to install the app on QRadar:
3
VMRay-QRadar App v1.0.0
4. To upload the VMRay extension, click Add > Browse, browse to the downloaded file, and
then click Add. Check Install immediately if you want to install integration after uploading
it.
5. After the installation is successful. The VMRay app is shown as installed in the Extension
Management window.
4
VMRay-QRadar App v1.0.0
5
VMRay-QRadar App v1.0.0
1. Open the QRadar Log Source Management app from the QRadar console.
6
VMRay-QRadar App v1.0.0
3. On the Select Log Source Type page, select VMRay Analyzer and click Select Protocol
Type.
Fig. Log Source Type Selection in QRadar Log Source Management App
4. Select a Syslog protocol and click Configure Log Source Parameters on the Select
Protocol Type page.
7
VMRay-QRadar App v1.0.0
5. On the Configure the Log Source parameters page, enter the log source parameters,
similar to the first approach in Configure Log Sources for VMRay Analyzer (Approach
1) of this document.
6. On the Configure the Log Source parameters page, make sure to uncheck Coalescing
Events to avoid grouping of the events on the basis of Source and Destination IP and
then click Configure Protocol Parameters.
7. On the Configure the protocol parameters page, specify the Log Source Identifier.
Also, specify the encoding of the data that will be received.
8
VMRay-QRadar App v1.0.0
9
VMRay-QRadar App v1.0.0
2. Add the API key that you have acquired from Analysis Settings » API Keys
page of your VMRay Analyzer server. Enter the server address and click on
‘Submit’. You can also configure the Polling Interval and Historical Polling Day.
Polling Interval: The frequency of the connector to pull events from VMRay
Analyzer.
Historical Polling Day: The period that the logs will be pulled retrospectively
from VMRay Analyzer on the first run of the connector.
10
VMRay-QRadar App v1.0.0
4. Once the integration is configured, it will start polling the VMRay server for new events and
these will be seen in QRadar’s Log Activity tab.
11
VMRay-QRadar App v1.0.0
6. You should only see the VMRay Analyzer events in the event table .
12
VMRay-QRadar App v1.0.0
13
VMRay-QRadar App v1.0.0
1. Go to the VMRay Analyzer Dashboard and you should be able to see the VMRay
Dashboard as shown below,
14
VMRay-QRadar App v1.0.0
1. Filter
a. Date Filter: Filters the Dashboard by date.
2. Metrics:
a. Submission: Shows the count of submissions made.
b. Analysis: Shows the count of analyses performed on Samples.
c. Submission with Errors: Shows the count of submission which had errors.
15
VMRay-QRadar App v1.0.0
3. Pie Charts:
a. Sample Types: Pie Chart for different Sample Types
16
VMRay-QRadar App v1.0.0
4. Tables:
a. Top Threat Names: Displays the top threat names detected.
17
VMRay-QRadar App v1.0.0
c. Top MITRE ATT&CK: Displays the top MITRE ATT&CK techniques detected.
18
VMRay-QRadar App v1.0.0
19
VMRay-QRadar App v1.0.0
20
VMRay-QRadar App v1.0.0
21
VMRay-QRadar App v1.0.0
22
VMRay-QRadar App v1.0.0
23
VMRay-QRadar App v1.0.0
24
VMRay-QRadar App v1.0.0
25
VMRay-QRadar App v1.0.0
3. As we can see in the groups, this right click action is currently only working for the URL
custom property. It means this right click action won’t be applicable for other custom
properties of other logs in which there are some form of URLs but with a different custom
property name.
4. To add this right click action for other custom properties of URLs for other logs (here we
will be adding it for ‘WebIf URL’), add them to the groups field.
26
VMRay-QRadar App v1.0.0
3. A list of installed applications and their App-ID values are output to the screen:
7. If you are QRoc/non admin users, Please follow the steps in this page to collect
application logs along with all the logs from the user interface.
These steps should have been able to help you troubleshoot your application. Please contact
VMRay Support if you need any further support.
27