{
 "categories": [
  "enterprise",
  "observability"
 ],
 "deployment": "hybrid",
 "evidence": [
  {
   "date": "2026-09-11",
   "fact": "homepage",
   "note": "IBM presents QRadar SIEM as a SIEM for centralized security visibility, real-time threat detection, and analyst investigation.",
   "source": "https://www.ibm.com/products/qradar-siem",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "deployment",
   "note": "IBM documents the REST API on the QRadar SIEM Console. Combined with the commercial product page, this record treats deployment as hybrid console software rather than a single public SaaS URL.",
   "source": "https://www.ibm.com/docs/api/v1/content/SS42VS_SHR/com.ibm.qradarapi.doc/c_rest_api_getting_started.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "license",
   "note": "The opened product page presents a commercial IBM SIEM offering, not a public free service.",
   "source": "https://www.ibm.com/products/qradar-siem",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "status",
   "note": "The page is a current IBM product listing with live features, use cases, and customer quotes.",
   "source": "https://www.ibm.com/products/qradar-siem",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "modalities.api.exists",
   "note": "IBM documents a RESTful API accessed by sending HTTPS requests to endpoints on the QRadar SIEM Console.",
   "source": "https://www.ibm.com/docs/api/v1/content/SS42VS_SHR/com.ibm.qradarapi.doc/c_rest_api_getting_started.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "modalities.api.kinds[0]",
   "note": "An API endpoint is a URL plus an HTTP method: GET, POST, PUT, or DELETE.",
   "source": "https://www.ibm.com/docs/api/v1/content/SS42VS_SHR/com.ibm.qradarapi.doc/c_rest_api_getting_started.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "modalities.api.auth[0]",
   "note": "IBM documents HTTP basic authentication with a QRadar username and password in the authorization header. IBM says this option is supported for the Documentation Page and is not the recommended integration path.",
   "source": "https://www.ibm.com/docs/api/v1/content/SS42VS_SHR/com.ibm.qradarapi.doc/c_rest_api_getting_started.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "modalities.api.auth[1]",
   "note": "IBM documents authorized-service tokens in the SEC header and recommends those tokens for all API integrations. Tokens inherit assigned roles and security profiles and remain valid until the configured expiry.",
   "source": "https://www.ibm.com/docs/api/v1/content/SS42VS_SHR/com.ibm.qradarapi.doc/c_rest_api_getting_started.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "modalities.api.coverage",
   "note": "Opened REST API Version 29.0 references listing /siem/offenses, /ariel/searches, reference_data, analytics, and other console resources. Coverage is the published endpoint set for that API version, not every QRadar UI function.",
   "source": "https://ibmsecuritydocs.github.io/qradar_api_29.0/",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "modalities.api.docs",
   "note": "Opened IBM Documentation content for QRadar API endpoint documentation and supported versions, including auth and the note that API 12.0 and later docs are hosted on GitHub.",
   "source": "https://www.ibm.com/docs/api/v1/content/SS42VS_SHR/com.ibm.qradarapi.doc/c_rest_api_getting_started.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "modalities.data_access.export[0]",
   "note": "IBM states most resources format the HTTP response body as JSON.",
   "source": "https://www.ibm.com/docs/api/v1/content/SS42VS_SHR/com.ibm.qradarapi.doc/c_rest_api_getting_started.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "modalities.mcp.first_party",
   "note": "IBM's MCP catalog lists QRadar SIEM Official MCP Server at github.com/IBM/qradar-mcp for searching offenses, running AQL, managing reference sets, and investigating incidents via the QRadar REST API.",
   "source": "https://github.com/IBM/mcp",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "modalities.mcp.first_party",
   "note": "The IBM/qradar-mcp README titles the project IBM QRadar MCP Server - Official and describes an open-source MCP server for QRadar SIEM.",
   "source": "https://raw.githubusercontent.com/IBM/qradar-mcp/main/README.md",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "modalities.mcp.verdict",
   "note": "README claims 83 tools and dual authentication. The IBM Public Repository Disclosure on the same page says the code is not an IBM product and IBM will not maintain it going forward. GitHub reports last push 2026-08-26 and the repo is not archived.",
   "source": "https://raw.githubusercontent.com/IBM/qradar-mcp/main/README.md",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "verdict.scores.api",
   "note": "Versioned REST with documented basic and SEC-token auth and a public GitHub endpoint index through API 29.0 is a practical production path. Interactive docs also live on each console at /api_doc/, and version headers are required to avoid breakages.",
   "source": "https://ibmsecuritydocs.github.io/qradar_api_overview/",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "verdict.scores.mcp",
   "note": "Official catalog listing and a populated README with broad tool categories, offset by the vendor disclosure that the server is OSS, not an IBM product, and will not be maintained.",
   "source": "https://raw.githubusercontent.com/IBM/qradar-mcp/main/README.md",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "freshness.watch[0].url",
   "note": "Opened the current IBM QRadar SIEM product page.",
   "source": "https://www.ibm.com/products/qradar-siem",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "freshness.watch[1].url",
   "note": "Opened IBM's MCP catalog listing QRadar SIEM Official MCP Server.",
   "source": "https://github.com/IBM/mcp",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "freshness.watch[2].url",
   "note": "Opened the vendor-owned IBM/qradar-mcp repository page.",
   "source": "https://github.com/IBM/qradar-mcp",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "freshness.watch[3].url",
   "note": "Opened the current QRadar MCP README, including the 83-tool category list, auth modes, and the IBM Public Repository Disclosure.",
   "source": "https://raw.githubusercontent.com/IBM/qradar-mcp/main/README.md",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "freshness.watch[4].url",
   "note": "Opened the IBM Documentation content API topic for QRadar REST API versions and authentication.",
   "source": "https://www.ibm.com/docs/api/v1/content/SS42VS_SHR/com.ibm.qradarapi.doc/c_rest_api_getting_started.html",
   "tier": "declared"
  },
  {
   "date": "2026-09-11",
   "fact": "freshness.watch[5].url",
   "note": "Opened the GitHub-hosted QRadar REST API overview that links API versions 12.0 through 29.0.",
   "source": "https://ibmsecuritydocs.github.io/qradar_api_overview/",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-09-11",
  "volatility": "medium",
  "watch": [
   {
    "type": "product",
    "url": "https://www.ibm.com/products/qradar-siem"
   },
   {
    "type": "mcp",
    "url": "https://github.com/IBM/mcp"
   },
   {
    "type": "mcp",
    "url": "https://github.com/IBM/qradar-mcp"
   },
   {
    "type": "docs",
    "url": "https://raw.githubusercontent.com/IBM/qradar-mcp/main/README.md"
   },
   {
    "type": "docs",
    "url": "https://www.ibm.com/docs/api/v1/content/SS42VS_SHR/com.ibm.qradarapi.doc/c_rest_api_getting_started.html"
   },
   {
    "type": "docs",
    "url": "https://ibmsecuritydocs.github.io/qradar_api_overview/"
   }
  ]
 },
 "homepage": "https://www.ibm.com/products/qradar-siem",
 "id": "ibm-qradar",
 "license": "commercial",
 "modalities": {
  "agent_docs": {
   "llms_txt": "unknown"
  },
  "api": {
   "auth": [
    "basic",
    "authorized-service-token"
   ],
   "coverage": "partial",
   "docs": "https://www.ibm.com/docs/api/v1/content/SS42VS_SHR/com.ibm.qradarapi.doc/c_rest_api_getting_started.html",
   "exists": true,
   "kinds": [
    "rest"
   ]
  },
  "cli": {
   "exists": "unknown"
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "json"
   ],
   "import": []
  },
  "extensibility": {
   "scripting": [],
   "webhooks": "unknown"
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": true,
   "third_party": [],
   "verdict": "official"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. The QRadar REST API and the vendor-owned qradar-mcp server are the supported automation paths. The QRadar Console UI remains unassessed.\n",
   "ui_stack": [],
   "vendor_support": []
  },
  "sdk": {
   "exists": "unknown",
   "languages": [],
   "official": "unknown"
  }
 },
 "name": "IBM QRadar SIEM",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "splunk",
   "crowdstrike-falcon",
   "wiz"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "IBM",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 7,
   "cli": null,
   "computer_use": null,
   "integrations": null,
   "mcp": 6,
   "overall": 7,
   "rpa": null
  },
  "summary": "IBM QRadar SIEM is automatable today through the console REST API. Agents send HTTPS requests to endpoints on the QRadar Console with either HTTP basic credentials or an authorized-service token in the SEC header. IBM recommends tokens for integrations. Most resources return JSON. API versions track QRadar releases; the opened topic lists QRadar 7.6.0 introducing REST API 29.0. IBM hosts endpoint documentation on GitHub at ibmsecuritydocs.github.io, including an overview that links API 12.0 through 29.0, and on each console at /api_doc/. Opened version-29 references include GET and POST /siem/offenses, /ariel/searches, and reference_data collections. The IBM/qradar-mcp repository is listed on IBM/mcp as QRadar SIEM Official MCP Server. The opened README, which is populated, claims 83 tools across offense management, Ariel/AQL search, reference data, analytics, log sources, assets, forensics, QVM, and configuration, with user-session SEC/CSRF or authorized-service tokens. The tools/ tree contains matching packages named offense, ariel, reference_data, analytics, log_source, asset, config, forensics, qvm, services, and system. This pass does not invent individual tool function names beyond those README category statements. The same README's IBM Public Repository Disclosure states the code is an open-source project, not an IBM product, and that IBM will not maintain it going forward. This record is QRadar SIEM. It is not Microsoft Sentinel. iPaaS connectors were not opened. Computer-use viability is unassessed. API scores 7 and is the best path. MCP scores 6 because coverage is useful but the vendor disclosure withholds product support and ongoing maintenance.\n"
 }
}