QRadar SIEM API 101 Walk-Through

I thought I'd share how I got the QRadar API working.

I downloaded the sample API python modules (,, etc.) from github

I downloaded the sample API script ( from github

I saved them all to the same folder.

I made sure I had python3 installed (not 2).

Then I had to download our console website PEM from the certificate like so and save it to the same folder.

Then I had to create an authorized service/token.

Then run the script via

It will prompt you to enter your authorization token (from the authorized service screen above) and your certificate location (copy the full path to the .crt file). Once you hit enter, you have the choice to save this token and certificate information to a plaintext file for future use. But then the API call runs and boom you have a list of all offenses!

