Skip to main content

QIDmap Information for QRadar SIEM Integration

Vendors have the ability to create what is called a QIDmap. The purpose of the mapping file is to create a listing of the events that the vendor can provide. It also creates a mapping that IBM consumes, producing a DSM. Once the DSM is in place, QRadar can take Threat Prevention events and categorize them.

The built-in low-level categories have two levels:

  • IBM will look to see if it can match the EventID field AND the Event Category field. If a match is found, the data will be displayed using the Event Name Threat Prevention supplied in the QIDmap. The data will be linked to the defined Low Level Category.

  • If no EventID field match is found, IBM will default back to just the Event Category field. The fallback ID of 19001 is IBM’s collection of general auditing information.

EventIDEvent CategoryLow Level CategoryEvent Name
general auditing informationObject Added19001Active Directory Object Created
Active DirectorycomputerObject AddedFalseTrueObject Added3041Active Directory Computer Creation Blocked by Threat Prevention
Active DirectorycomputerObject AddedTrueFalseObject Added3041Active Directory Computer Created
Active DirectorygroupObject AddedFalseTrueObject Added3038Active Directory Group Creation Blocked by Threat Prevention
Active DirectorygroupObject AddedTrueFalseObject Added3038Active Directory Group Created
Active DirectoryuserObject AddedFalseTrueObject Added3031Active Directory User Creation Blocked by Threat Prevention
Active DirectoryuserObject AddedFalseTrueObject Added3031Active Directory User Created
general auditing informationObject Deleted19001Active Directory Object Deleted
Active DirectorycomputerObject DeletedFalseTrueObject Deleted3043Active Directory Computer Deletion Blocked by Threat Prevention
Active DirectorycomputerObject DeletedFalseTrueObject Deleted3043Active Directory Computer Deleted
Active DirectorygroupObject DeletedFalseTrueObject Deleted3040Active Directory Group Deletion Blocked by Threat Prevention
Active DirectorygroupObject DeletedFalseTrueObject Deleted3040Active Directory Group Deleted
Active DirectoryuserObject DeletedFalseTrueObject Deleted3035Active Directory User Deletion Blocked by Threat Prevention
Active DirectoryuserObject DeletedFalseTrueObject Deleted3035Active Directory User Deleted
general auditing informationObject Modified19001Active Directory Object Modified
Active DirectorycomputerObject ModifiedFalseTrueObject Modified3042Active Directory Computer Modification Blocked by Threat Prevention
Active DirectorycomputerObject ModifiedFalseTrueObject Modified3042Active Directory Computer Modified
Active DirectorygroupObject ModifiedFalseTrueObject Modified3039Active Directory Group Modification Blocked by Threat Prevention
Active DirectorygroupObject ModifiedFalseTrueObject Modified3039Active Directory Group Modified
Active DirectoryuserObject ModifiedFalseTrueObject Modified3032Active Directory User Modification Blocked by Threat Prevention
Active DirectoryuserObject ModifiedFalseTrueObject Modified3032Active Directory User Modified
general auditing informationObject Moved/Renamed19001Active Directory Object Moved or Renamed
Active DirectorycomputerObject Moved/RenamedFalseTrueObject Moved/Renamed3042Active Directory Computer Move or Rename Blocked by Threat Prevention
Active DirectorycomputerObject Moved/RenamedFalseTrueObject Moved/Renamed3042Active Directory Computer Moved or Renamed
Active DirectorygroupObject Moved/RenamedFalseTrueObject Moved/Renamed3039Active Directory Group Move or Rename Blocked by Threat Prevention
Active DirectorygroupObject Moved/RenamedFalseTrueObject Moved/Renamed3039Active Directory Group Moved or Renamed
Active DirectoryuserObject Moved/RenamedFalseTrueObject Moved/Renamed3032Active Directory User Move or Rename Blocked by Threat Prevention
Active DirectoryuserObject Moved/RenamedFalseTrueObject Moved/Renamed3032Active Directory User Moved or Renamed
GPO LockdownAddFalseTrueAdd3030GPO Setting Modification Blocked by Threat Prevention
GPO LockdownDeleteFalseTrueDelete3030GPO Setting Modification Blocked by Threat Prevention
SI Events LogGPO AddedTrueFalseGPO Added3030Active Directory Group Policy Object Setting Defined
SI Events LogGPO DeletedTrueFalseGPO Deleted3030Active Directory Group Policy Object Setting Undefined
SI Events LogGPO ModifiedTrueFalseGPO Modified3030Active Directory Group Policy Object Modified
SI Events LogGPO RenamedTrueFalseGPO Renamed3030Active Directory Group Policy Object Modified
SI Events LogGPO UntranslatedTrueFalseGPO Untranslated3030Active Directory Group Policy Object Modified
Windows File SystemAccess Rights ChangeTrueFalseAccess Rights Change8014Windows File System Folder or File Access Rights Change
Windows File SystemAttribute ChangeTrueFalseAttribute Change8014Windows File System Folder or File Attribute Change
Windows File SystemAudit Config ChangeTrueFalseAudit Config Change8014Windows File System Folder or File Config Change
Windows File SystemCreateTrueFalseCreate8028Windows File System Folder or File Create
Windows File SystemDeleteTrueFalseDelete8033Windows File System Folder or File Delete
Windows File SystemOwnerTrueFalseOwner8014Windows File System Folder or File Owner Change
Windows File SystemReadTrueFalseRead8014Windows File System Folder or File Read
Windows File SystemRenameTrueFalseRename8014Windows File System Folder or File Rename
Windows File SystemUpdateTrueFalseUpdate8014Windows File System Folder or File Update
Workstation EventsLockTrueFalseLock3004Workstation Locked
Workstation EventsLog OffTrueFalseLog Off3004Workstation Log Off
Workstation EventsLog OnTrueFalseLog On3004Workstation Log On
Workstation EventsScreen Saver StartTrueFalseScreen Saver Start3004Workstation Screen Saver Start
Workstation EventsScreen Saver StopTrueFalseScreen Saver Stop3004Workstation Screen Saver Stop
Workstation EventsUnlockTrueFalseUnlock3004Workstation Unlocked