Skip to main content
IBM QRadar SOAR Add-on for Splunk app icon

IBM QRadar SOAR Add-on for Splunk

The QRadar SOAR Add-on integrates the IBM Security QRadar SOAR Platform with Splunk to simplify and streamline the process of escalating and managing cases. Escalating a Splunk alert or Splunk ES notable event to IBM QRadar SOAR allows the platform to generate a detailed, case-specific response plan that enables security team members to quickly respond.Built by IBM QRadar SOAR
splunk product badge

Default Version 2.4.1

April 27, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 6.x, 5.x, 4.x

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

The QRadar SOAR Add-on integrates the IBM Security QRadar SOAR Platform with Splunk to simplify and streamline the process of escalating and managing cases. Escalating a Splunk alert or Splunk ES notable event to IBM QRadar SOAR allows the platform to generate a detailed, case-specific response plan that enables security team members to quickly respond. Additionally, security team members can add artifacts and other incident details to case records, and can leverage built-in threat intelligence to gather valuable context needed to inform an intelligent and decisive response. Complete documentation is available on GitHub: https://github.com/ibmresilient/resilient-reference/tree/master/developer_guides/qradar-soar-splunk-addon For support, please visit https://ibm.com/mysupport . Do not use the "Contact Developer" link, as that email address is not monitored.