commonfields: id: QRadar v3 version: -1 sectionorder: - Connect - Collect name: QRadar v3 display: IBM QRadar v3 category: Analytics & SIEM provider: Palo Alto Networks description: IBM QRadar SIEM helps security teams accurately detect and prioritize threats across the enterprise, supports API versions 10.1 and above. Provides intelligent insights that enable teams to respond quickly to reduce the impact of incidents. configuration: - display: Server URL name: server type: 0 required: true additionalinfo: (e.g., https://192.168.0.1) section: Connect - display: Username name: credentials type: 9 required: true section: Connect - display: QRadar API Version defaultvalue: 17.0 additionalinfo: API version of QRadar (e.g., '12.0'). Minimum API version is 10.1. Since QRadar API v19, The timestamp fields should be provided as milliseconds epoch format instead of seconds. name: api_version type: 0 required: true section: Connect - display: Incident Type name: incident_type type: 13 section: Connect required: false - defaultvalue: 3 days additionalinfo: if no offenses are found within the range of first fetch, will be set to fetch the earliest offense. display: First fetch timestamp (