Can AI agents automate IBM QRadar SIEM?

IBM · hybrid · enterpriseobservability

IBM QRadar SIEM is automatable today through the console REST API. Agents send HTTPS requests to endpoints on the QRadar Console with either HTTP basic credentials or an authorized-service token in the SEC header. IBM recommends tokens for integrations. Most resources return JSON. API versions track QRadar releases; the opened topic lists QRadar 7.6.0 introducing REST API 29.0. IBM hosts endpoint documentation on GitHub at ibmsecuritydocs.github.io, including an overview that links API 12.0 through 29.0, and on each console at /api_doc/. Opened version-29 references include GET and POST /siem/offenses, /ariel/searches, and reference_data collections. The IBM/qradar-mcp repository is listed on IBM/mcp as QRadar SIEM Official MCP Server. The opened README, which is populated, claims 83 tools across offense management, Ariel/AQL search, reference data, analytics, log sources, assets, forensics, QVM, and configuration, with user-session SEC/CSRF or authorized-service tokens. The tools/ tree contains matching packages named offense, ariel, reference_data, analytics, log_source, asset, config, forensics, qvm, services, and system. This pass does not invent individual tool function names beyond those README category statements. The same README's IBM Public Repository Disclosure states the code is an open-source project, not an IBM product, and that IBM will not maintain it going forward. This record is QRadar SIEM. It is not Microsoft Sentinel. iPaaS connectors were not opened. Computer-use viability is unassessed. API scores 7 and is the best path. MCP scores 6 because coverage is useful but the vendor disclosure withholds product support and ongoing maintenance.

Best path today: api · Overall automatability: 7/10

Modalities

ModalityStatusDetail
APIyesrestbasicauthorized-service-token
coverage: partial · docs
SDKunknown
official: unknown
MCPyes
verdict: official
Integrationsunknown
CLIunknown
Extensibilityunknown
webhooks: unknown
Data access
export: json · import: unknown
RPA / UI automationunknown
No repeatable UI probe was run. The QRadar REST API and the vendor-owned qradar-mcp server are the supported automation paths. The QRadar Console UI remains unassessed.
Computer useunknown
measured verdicts only — "unknown" means not yet probed by us

Scores

apimcpintegrationsclirpacomputer useoverall
767

Evidence

FactTierSourceDate
homepagedeclaredsource2026-09-11
deploymentdeclaredsource2026-09-11
licensedeclaredsource2026-09-11
statusdeclaredsource2026-09-11
modalities.api.existsdeclaredsource2026-09-11
modalities.api.kinds[0]declaredsource2026-09-11
modalities.api.auth[0]declaredsource2026-09-11
modalities.api.auth[1]declaredsource2026-09-11
modalities.api.coveragedeclaredsource2026-09-11
modalities.api.docsdeclaredsource2026-09-11
modalities.data_access.export[0]declaredsource2026-09-11
modalities.mcp.first_partydeclaredsource2026-09-11
modalities.mcp.first_partydeclaredsource2026-09-11
modalities.mcp.verdictdeclaredsource2026-09-11
verdict.scores.apideclaredsource2026-09-11
verdict.scores.mcpdeclaredsource2026-09-11
freshness.watch[0].urldeclaredsource2026-09-11
freshness.watch[1].urldeclaredsource2026-09-11
freshness.watch[2].urldeclaredsource2026-09-11
freshness.watch[3].urldeclaredsource2026-09-11
freshness.watch[4].urldeclaredsource2026-09-11
freshness.watch[5].urldeclaredsource2026-09-11

Related tools

Other products in this database that share a category with IBM QRadar SIEM.

Last verified 2026-09-11 · volatility medium · JSON record