---
name: azion-send-logs-to-ibm-qradar
description: >-
  Create a stream that sends the logs of your applications to the URL of an IBM QRadar instance, in Azion Console or with the Azion API, and confirm the delivery.
---

# Send logs to IBM QRadar

You can send the logs of a stream to [IBM QRadar](https://www.ibm.com/qradar) from Azion Console or with the Azion API. To send the events of a Web Application Firewall to a SIEM instead of the requests of your applications, refer to [Stream WAF events to a SIEM](/en/documentation/guides/application-security/firewall-and-waf/integrate-siems/).

[Data Stream](/en/documentation/platform/data-stream/) sends each batch of log lines to a URL of your QRadar instance. The URL is the only setting of this endpoint, with no key or token to enter. The stream form sets the endpoint in the field labeled **Connector**, where QRadar is the *IBM QRadar* option. For the field and its bounds, refer to [Endpoints](/en/documentation/platform/data-stream/endpoints/#ibm-qradar).

This guide streams the requests of one workload through the *Applications* data source.

---

Select your interface here. The prerequisites and the tasks below follow that choice.

## Prerequisites

- An Azion account with the **Edit Data Stream** permission. For the permissions, refer to [Stream settings](/en/documentation/platform/data-stream/stream-settings/#permissions).
- A [workload](/en/documentation/platform/workloads/) on the account that receives requests.
- Access to your IBM QRadar instance, to get the URL that receives the log lines.
- That URL, with its scheme, such as `https://qradar.example.com:14440`.

**Console**

- Access to Azion Console. To sign in, refer to [How to access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).

**API**

- A personal token. To create one, refer to [How to manage a personal token](/en/documentation/guides/platform/account-and-billing/personal-tokens/).
- The ID of the workload.
- `curl`.

---

## Create the stream

The stream takes its logs from one workload, through a workload filter. Sampling would deactivate your other streams; a workload filter does not.

**Console**

To create the stream in Azion Console:

1. **Open Data Stream**

   Access [Azion Console](https://console.azion.com/) > **Data Stream**.

2. **Select + Stream**

3. **Name the stream**

   In the **General** section, enter a **Name**. For example: `logs-to-qradar`.

4. **Select the data source**

   In the **Input** section, select *Applications* in **Data Source**.

5. **Turn off Sampling**

   In the **Transform** section, turn off **Sampling** while **Option** is still *All Current and Future Workloads*, its starting value. A stream cannot carry sampling and a workload filter together.

6. **Choose the workload**

   In the **Transform** section, set **Option** to *Filter Workloads*. Select your workload in **Available Workload**, then use the arrow to move it to **Chosen Workload**.

7. **Select the template**

   In the **Render Template** section, select *Applications Event Collector* in **Template**.

8. **Select the QRadar endpoint**

   In the **Output** section, select *IBM QRadar* in **Connector**.

9. **Enter the QRadar URL**

   In **URL**, enter the URL of your QRadar instance. For example: `https://qradar.example.com:14440`.

10. **Keep the stream active**

    In the **Status** section, leave **Active** on.

11. **Select Save**

The Console confirms with `Your data stream has been created`. In the **Data Stream** list, the stream shows `QRadar` in the **Connector** column and the **Active** status.

**API**

Send a `POST` request to `https://api.azion.com/v4/workspace/stream/streams`. In the body, replace `<workload-id>` with the ID of your workload and the `url` value with the URL of your QRadar instance. Replace `[TOKEN VALUE]` with your personal token:

```bash
curl -X POST 'https://api.azion.com/v4/workspace/stream/streams' \
  -H 'Content-Type: application/json' \
  -H 'Authorization: Token [TOKEN VALUE]' \
  -d '{
    "name": "logs-to-qradar",
    "active": true,
    "inputs": [
      { "type": "raw_logs", "attributes": { "data_source": "workloads" } }
    ],
    "transform": [
      { "type": "filter_workloads", "attributes": { "workloads": [<workload-id>] } },
      { "type": "render_template", "attributes": { "template": 2 } }
    ],
    "outputs": [
      {
        "type": "qradar",
        "attributes": {
          "url": "https://qradar.example.com:14440"
        }
      }
    ]
  }'
```

The data source `workloads` is the API name of *Applications*, and template `2` is *Applications Event Collector*. The `qradar` endpoint takes `url` as its only attribute. The API answers `201` and returns the stored stream:

```json
{
  "state": "executed",
  "data": {
    "id": 12355,
    "name": "logs-to-qradar",
    "last_editor": "user@example.com",
    "created": "2026-01-01T12:10:40.000000Z",
    "last_modified": "2026-01-01T12:10:40.000000Z",
    "product_version": "1.0",
    …
    "outputs": [
      {
        "type": "qradar",
        "attributes": {
          "url": "https://qradar.example.com:14440"
        }
      }
    ]
  }
}
```

The `id` identifies the stream in later requests, such as `/v4/workspace/stream/streams/12355`. For every key of the body, refer to [Stream settings](/en/documentation/platform/data-stream/stream-settings/#stream-object).

Azion saves the stream without a call to the QRadar URL. A wrong URL shows only when the stream sends. The activation takes effect after one to two minutes.

---

## Confirm the delivery

[Real-Time Events](/en/documentation/platform/real-time-events/data-sources/#data-stream) keeps a record of each send of a stream, delivered or not, with the status code that the endpoint returned. Send a few requests to the workload and wait about one minute. A stream sends a batch every 60 seconds, or earlier when the batch reaches 2,000 log lines.

**Console**

To read the sends in Azion Console:

1. **Open Real-Time Events**

   Access [Azion Console](https://console.azion.com/) > **Real-Time Events**.

2. **Select the Data Stream data source**

3. **Find the QRadar sends**

   Each row is one send. Look for `QRADAR` in **Endpoint Type**, and read the **Status Code** of those rows.

A `200` in **Status Code** means QRadar accepted the batch. **Streamed Lines** shows how many log lines the batch held.

**API**

To read the sends with the API, query the `dataStreamedEvents` dataset of the Real-Time Events GraphQL API. Set the dates to a range that includes the activation of the stream:

```bash
curl -X POST 'https://api.azion.com/v4/events/graphql' \
  -H 'Content-Type: application/json' \
  -H 'Authorization: Token [TOKEN VALUE]' \
  -d '{"query":"query { dataStreamedEvents(limit: 20, filter: {tsRange: {begin: \"2026-01-01T12:00:00\", end: \"2026-01-01T12:45:00\"}}, orderBy: [ts_DESC]) { ts endpointType statusCode streamedLines dataStreamed } }"}'
```

The API answers `200` with one record per send, the latest first:

```json
{
  "data": {
    "dataStreamedEvents": [
      {
        "ts": "2026-01-01T12:02:04Z",
        "endpointType": "QRADAR",
        "statusCode": 200,
        "streamedLines": 2,
        "dataStreamed": 2797
      }
    ]
  }
}
```

A send to QRadar carries `QRADAR` in `endpointType`. A `statusCode` of `200` means QRadar accepted the batch. The `streamedLines` and `dataStreamed` fields give the size of the batch in log lines and in bytes. If `dataStreamedEvents` is an empty list, the stream did not send in that range. For every field, refer to [Real-Time Events GraphQL fields](/en/documentation/devtools/graphql/gql-real-time-events-fields/#datastreamedevents-data-stream).

A status other than `200` comes from QRadar, except `503`: that status means Data Stream found the endpoint unavailable. For the causes, refer to [Troubleshoot Data Stream](/en/documentation/platform/data-stream/troubleshooting/).

---

## Next steps

- [Endpoints](/en/documentation/platform/data-stream/endpoints.md#ibm-qradar): The URL field of the IBM QRadar endpoint, with its type and API name.
- [Stream WAF events to a SIEM](/en/documentation/guides/application-security/firewall-and-waf/integrate-siems.md): Send the events of a Web Application Firewall to QRadar or another SIEM.
- [Edit, stop, or delete a stream](/en/documentation/guides/platform/observability/delete-data-stream.md): Change the QRadar URL, pause the stream, or remove it.
- [Troubleshoot Data Stream](/en/documentation/platform/data-stream/troubleshooting.md): Find what to change when a send returns a status other than 200.
