# Using Elastic Security as SOAR for IBM QRadar SIEM (Log Forwarding Architecture)

**URL:** <https://discuss.elastic.co/t/using-elastic-security-as-soar-for-ibm-qradar-siem-log-forwarding-architecture/385893>\
**Category:** SIEM\
**Created:** [April 15, 2026, 6:33am UTC](https://discuss.elastic.co/t/using-elastic-security-as-soar-for-ibm-qradar-siem-log-forwarding-architecture/385893 "2026-04-15T06:33:04Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![PatreKerier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrekerier/32/141214_2.png) [@PatreKerier](https://discuss.elastic.co/u/PatreKerier)\
**Post date:** [April 15, 2026, 6:33am UTC](https://discuss.elastic.co/t/using-elastic-security-as-soar-for-ibm-qradar-siem-log-forwarding-architecture/385893/1 "2026-04-15T06:33:04Z")

</div>

Hi everyone,

I'm working on a project to integrate IBM QRadar SIEM with Elastic Security. The goal is to use Elastic specifically for its SOAR capabilities (Case Management, Automation, Response Actions) while keeping QRadar as the primary log collector.

The setup:

- All logs are currently ingested by QRadar.

- I want to forward these logs to Elastic without redeploying agents (like Elastic Agent) to the endpoints.

- Elastic should act as the incident management and orchestration layer.

My questions:

1. Ingestion Strategy: What is the best practice for forwarding data from QRadar? Should I use a standard Syslog Destination (LEEF format) or poll the QRadar API for Offenses/Events via Logstash?

2. ECS Mapping: Does anyone have experience mapping QRadar LEEF fields to Elastic Common Schema (ECS)? I'm looking for Logstash configurations or Ingest Pipelines to ensure the "Security" app in Elastic correctly recognizes the data.

3. SOAR Efficiency: Since I won't have Elastic Agents on the hosts for "Response Actions" (like host isolation), how far can I get with Webhook/Rest API connectors for automated response?

Any advice, architecture diagrams, or common pitfalls would be greatly appreciated. Thanks!

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 16, 2026, 5:41am UTC](https://discuss.elastic.co/t/using-elastic-security-as-soar-for-ibm-qradar-siem-log-forwarding-architecture/385893/2 "2026-04-16T05:41:39Z")

</div>

I think this scenario is pretty rare and I'm not sure if this makes much sense to implement.

The features you mentioned that you want to use basically requires that your data is indexed in Elasticsearch, so you would need to duplicate the data you have in QRadar into Elastic and create the Security Rules in Elastic search, not QRadar.

So to use SIEM features you would need to have your data duplicated in two different tools.

> [@PatreKerier](#):
>
> - Ingestion Strategy: What is the best practice for forwarding data from QRadar? Should I use a standard Syslog Destination (LEEF format) or poll the QRadar API for Offenses/Events via Logstash?
> - ECS Mapping: Does anyone have experience mapping QRadar LEEF fields to Elastic Common Schema (ECS)? I'm looking for Logstash configurations or Ingest Pipelines to ensure the "Security" app in Elastic correctly recognizes the data.

This depends a lot on what are your data sources, what kind of data are you indexing in QRadar? You would need to send the **raw** message from them to Elasticsearch and create the parsers yourself or if it is something that has a native integration you could use the ingest pipelines from the integration to parse the data, but this expect the raw data without any changes on the format.

This can be done using logstash as a proxy to receive the data and send it to the correct ingest pipeline, but since you are not using Elastic Agent to collect the data, this may require a lot of work.

> [@PatreKerier](#):
>
> 1. SOAR Efficiency: Since I won't have Elastic Agents on the hosts for "Response Actions" (like host isolation), how far can I get with Webhook/Rest API connectors for automated response?

This depends on the license, to use webhooks you need a paid license, platinum or enterprise, without it the only actions that Kibana can do is index the alert to an index or write the alert in the kibana log file.

You could use logstash to read the alerts index and perform some requests to webhook, but again, you would need to write the pipelines etc.

What exactly you want to send from QRadar to Elastic? Just alerts or the raw data?

---

<div class="post-metadata">

**Author:** ![PatreKerier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrekerier/32/141214_2.png) [@PatreKerier](https://discuss.elastic.co/u/PatreKerier)\
**Post date:** [April 16, 2026, 5:50am UTC](https://discuss.elastic.co/t/using-elastic-security-as-soar-for-ibm-qradar-siem-log-forwarding-architecture/385893/3 "2026-04-16T05:50:10Z")

</div>

Hello! We have the opportunity to install Elastic Agent on the hosts and we need this functionality: [Workflows | Elastic Docs](https://www.elastic.co/docs/explore-analyze/workflows)

Can you tell me if it is possible to implement this functionality during the free license?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 16, 2026, 1:02pm UTC](https://discuss.elastic.co/t/using-elastic-security-as-soar-for-ibm-qradar-siem-log-forwarding-architecture/385893/4 "2026-04-16T13:02:20Z")

</div>

> [@PatreKerier](#):
>
> Can you tell me if it is possible to implement this functionality during the free license?

No, Workflows requires an Enterprise license, it does not work with the basic license.

---

<div class="post-metadata">

**Author:** ![PatreKerier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrekerier/32/141214_2.png) [@PatreKerier](https://discuss.elastic.co/u/PatreKerier)\
**Post date:** [April 16, 2026, 1:19pm UTC](https://discuss.elastic.co/t/using-elastic-security-as-soar-for-ibm-qradar-siem-log-forwarding-architecture/385893/5 "2026-04-16T13:19:12Z")

</div>

A license that is issued for 30 days should be suitable, right?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 16, 2026, 1:41pm UTC](https://discuss.elastic.co/t/using-elastic-security-as-soar-for-ibm-qradar-siem-log-forwarding-architecture/385893/6 "2026-04-16T13:41:59Z")

</div>

> [@PatreKerier](#):
>
> A license that is issued for 30 days should be suitable, right?

For a test yes, the trial license will work for 30 days, after that it will stop working.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 14, 2026, 1:42pm UTC](https://discuss.elastic.co/t/using-elastic-security-as-soar-for-ibm-qradar-siem-log-forwarding-architecture/385893/7 "2026-05-14T13:42:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
