{% extends "base.html" %} {% block title %}Settings & DSM Config{% endblock %} {% block content %}

⚙️ DentiGrid & IBM QRadar Integration Configuration

Configure API connectors, LEEF 2.0 Syslog ingestion receivers, and autonomous SOAR response thresholds.

Cloud or on-premise DentiGrid tenant management URL.
Used for REST API synchronization and 1-click containment dispatch.
Standard QRadar Syslog port (UDP/TCP/TLS 514).
Automatically triggers EDR quarantine when Severity >= 9 (Canary Encryption, Shadow Copy Tamper).
Contributes verified zero-false-positive attacker IOCs to IBM Security X-Force.

📋 QRadar Log Source Configuration Quick Reference

Log Source Identifier: DentiGrid-LEEF-Receiver Log Source Type: DentiSystems DentiGrid Deception Platform (Log Source Type ID: 7050) Protocol Type: Syslog (TLS) Target QRadar Event Collector: Ingress EC-01 (10.0.100.10:514) Payload Format: LEEF 2.0 (Delimiter: Tab ' ') Custom DSM XML: dsm.xml Event Mapping XML: event-mapping.xml Reference Sets: DentiGrid_Quarantined_Hosts, DentiGrid_Decoy_IP_List
{% endblock %}