Skip to main content
Question

Qradar SIEM integration


Forum|alt.badge.img

I am trying to connect Box RESTAPI to our IBM Qradar SIEM for compliance management. I have followed the documents and video's however non of them identify what to use as the Log Source Identifier.

 

All other instructions to get ClientID, Secret, KeyID, EntID, and PrivKey have all been completed and supplied into Qradar interface.

 

I have attempted to use all of the below with no success.

https://api.box.com/

http://api.box.com/

api.box.com/

https://api.box.com/oauth2/token

https://account.box.com/api/

 

Failed - ERROR - Unable to collect events. 

3 replies

Forum|alt.badge.img

Hi,

Did you get this fixed ?

 


Forum|alt.badge.img

No. We are still struggling to get this active. It initially connects as a log source, but then errors out saying it cannot get any data.









Forum|alt.badge.img

I realize this post is rather old at this point - but it got us going down the right path, and we eventually got it figure out.

 

For event logs - your log source identifier URL needs to be:

https://api.box.com/2.0/events

After we set that, everything started flowing in with no issues.

I found this in the API user guide for Box - specifically in the "User Events" section.


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings