QRadar - Get offense correlations


Use the QRadar - Get offense correlations v2 instead.

Gets more information when running on a QRadar offense.

  • Get all correlations relevant to the offense
  • Get all logs relevant to the correlations. This is not done by default. To put this in place set GetCorrelationLogs to "True".


  • GetCorrelationLogs (default: False)
  • MaxLogsCount (default: 20)


This playbook uses the following sub-playbooks, integrations, and scripts.


This playbook does not use any sub-playbooks.


This playbook does not use any integrations.


  • QRadarGetCorrelationLogs
  • QRadarGetOffenseCorrelations


This playbook does not use any commands.

Playbook Inputs

NameDescriptionDefault ValueSourceRequired
GetCorrelationLogsGet all of the offense's correlations logs when set to "True".False-Optional
MaxLogsCountTHe maximum number of log entires to query from QRadar. The default is 20.20-Optional
IDThe QRadar offense ID.labels.idincidentRequired
StartTimeThe QRadar offense start time.labels.start_timeincidentRequired

Playbook Outputs

QRadar.Correlation.StartTimeThe correlation start time.unknown
QRadar.Correlation.CategoryIDThe correlation category ID.unknown
QRadar.Correlation.QIDThe correlation QID identifier.unknown
QRadar.Correlation.CRENameThe correlation name.unknown
QRadar.Correlation.CREDescriptionThe correlation description.unknown
QRadar.CorrelationThe QRadar offense correlations.unknown
QRadar.Correlation.SourceIPThe correlation source IP address.unknown
QRadarThe QRadar context output.unknown
QRadar.Correlation.DestinationIPThe correlation destination IP address.unknown
QRadar.Correlation.CategoryThe correlation high level category.unknown
QRadar.Correlation.UsernameThe correlation username.unknown
QRadar.LogThe QRadar offense correlation logs.unknown
QRadar.Log.QIDThe log's correlation ID.unknown
QRadar.Log.SourceIPThe log's source IP address.unknown
QRadar.Log.DestinationPortThe log's destination port.unknown
QRadar.Log.SourcePortThe log's source port.unknown
QRadar.Log.DestinationIPThe log's destination IP address.unknown
QRadar.Log.CategoryThe log's category.unknown
QRadar.Log.IdentityIPThe log's identity IP address.unknown
QRadar.Log.UsernameThe log's username.unknown
QRadar.Log.StartTimeThe log's start time.unknown
QRadar.Log.MagnitudeThe log's magnitude.unknown
QRadar.Log.ProtocolNameThe log's protocol name.unknown

Playbook Image