IBM QRadar: Developing QRadar Applications
Setup your environment
Install Docker
1) Install Docker-CE on RHEL/CentOS 8
sudo subscription-manager repos --enable codeready-builder-for-rhel-8-$(arch)-rpms sudo dnf install https://dl.fedoraproject.org/pub/epel/epel-release-latest-8.noarch.rpm sudo dnf install pass
Important: If you already have Podman/ContainerD, you must remove
sudo dnf uninstall podman runc
2) Start Docker-CE
sudo systemctl enable docker sudo systemctl start docker
3) Check Do
sudo usermod -aG docker <MY USER>
Install QRadar SDK
Download SDK from XForce
Cloning sample repository
Let's get some examples
1) Clone the repository and go to HelloWorld application
git clone https://github.com/IBM/qradar-sample-apps.git cd qradar-sample-apps/HelloWorld
2) Change manifest.json
Let's change the default image, with a new one.
"image": "qradar-app-base:4.0.0",
3) Run HelloWorld
qapp run
Deploy on QRadar
1) Create a package
qapp package -p app.zip
2) Deploy on QRadar
qapp deploy -p app.zip -q 192.168.42.150 -u admin