No logo available for IBM QRadar to DuckDB connector icon

Load IBM QRadar data to DuckDB

Build a IBM QRadar to DuckDB pipeline with your coding agent. One prompt scaffolds it with the dltHub AI harness, plus the IBM QRadar API base URL, auth, endpoints, and incremental loading.

SourceIBM QRadarIBM QRadar API DocumentationDestinationDuckDBIn-process analytical database. The default local destination for dlt pipelines.

IBM QRadar is a security information and event management platform providing a REST API to access, manage, and integrate with security data and configurations. Everything needed to build a working IBM QRadar → DuckDB pipeline is on this page: the API's base URL, authentication, endpoints, pagination and incremental field — plus a prompt that hands the whole job to your coding agent.


Build your IBM QRadar to DuckDB pipeline

Paste this prompt into Claude, Codex, or Cursor. The agent does the rest.

Prompt
Run uvx dlthub-init@latest to build a pipeline from IBM QRadar to DuckDB and run it on dltHub

That scaffolds a dltHub workspace and installs the dltHub AI harness — the project rules, the secrets-management skill, and the dlt MCP server your agent needs to work safely. From there it reads the IBM QRadar API, proposes the endpoints to load, then writes, runs and validates the pipeline while you review rather than type. Credentials are inspected through MCP tools, so your agent never reads secrets.toml itself. How the LLM-native workflow works →

Prefer to write it yourself? Every fact the agent uses is below.


IBM QRadar API at a glance

Base URLhttps://<console_ip>/api
Example endpointGET help/resources
Authenticationall requests require either an SEC header for tokens or an Authorization header for basic authentication — sent in the SEC header
PaginationNot paginated
Incremental fieldRange header parameter (paging)
API referencehttps://www.ibm.com/docs/en/qradar-common?topic=api-endpoint-documentation-supported-versions

These values come from the IBM QRadar API reference — the authoritative source if anything here looks out of date.


How do I authenticate with the IBM QRadar API?

Requests require an HTTP header for authentication; for authorized service tokens, use the 'SEC' header, and for username/password, use the standard 'Authorization' header with HTTP basic authentication.

1. Get your credentials

  1. Log into your IBM QRadar console. 2. Navigate to the Admin tab. 3. Under System Configuration, click User Management, then select Authorized Services. 4. Click Add Authorized Service. 5. Provide a name for the service, select a Security Profile, and assign a User Role (typically Admin). 6. Set an expiry date or choose 'No Expiry'. 7. Click Create Service. 8. In the Authorized Services Management window, select the newly created service and copy the token string from the Selected Token field. Note: The token is displayed only once; ensure you copy and save it securely before closing the window.

2. Add them to .dlt/secrets.toml

[sources.ibm_qradar_source] qradar_host = "your_qradar_console_ip_or_fqdn" sec_token = "your_authorized_service_token_here"

dlt reads this file automatically at runtime. With the harness, the setup-secrets skill prompts you for the values and never handles the raw credential in chat. For production, see setting up credentials with dlt.


What IBM QRadar data can I load into DuckDB?

These are the IBM QRadar endpoints dlt can load into DuckDB:

ResourceEndpointMethodData selectorDescription
help_resources/help/resourcesGETRetrieves a list of resource documentation objects.
help_endpoints/help/endpointsGETRetrieves a list of endpoint documentation objects.
siem_offenses/siem/offensesGETRetrieves a list of offenses.
analytics_rule_groups/analytics/rule_groupsGETRetrieves a list of rule groups.
ariel_databases/ariel/databasesGETRetrieves a list of Ariel databases.

How do I load only new IBM QRadar records?

IBM QRadar exposes Range header parameter (paging) on help/resources, so dlt can request only the records that changed since the last run. Set it as the cursor_path and dlt tracks the high-water mark for you between runs.

{"name": "help_resources", "endpoint": { "path": "help/resources", "incremental": {"cursor_path": "Range header parameter (paging)", "initial_value": "2024-01-01T00:00:00Z"}, }}

On the first run dlt loads everything from initial_value; on every run after that it requests only what changed and appends with write_disposition="merge" if you set a primary key. See incremental loading.


What does the generated IBM QRadar pipeline look like?

A standard dlt REST API pipeline — the same code you would write by hand, loading /ariel/searches and /config/access/authorized_services from the IBM QRadar API into DuckDB:

import dlt from dlt.sources.rest_api import RESTAPIConfig, rest_api_resources @dlt.source def ibm_qradar_source(api_token=dlt.secrets.value): config: RESTAPIConfig = { "client": { "base_url": "https://<console_ip>/api", "auth": {"type": "api_key", "api_key": api_token, "name": "SEC"}, }, "resources": [ {"name": "help_resources", "endpoint": {"path": "help/resources"}}, {"name": "help_endpoints", "endpoint": {"path": "help/endpoints"}} ], } yield from rest_api_resources(config) def load_ibm_qradar_to_duckdb() -> None: pipeline = dlt.pipeline( pipeline_name="ibm_qradar_pipeline", destination="duckdb", dataset_name="ibm_qradar_data", ) load_info = pipeline.run(ibm_qradar_source()) print(load_info) if __name__ == "__main__": load_ibm_qradar_to_duckdb()

Run it with python ibm_qradar_pipeline.py. The agent iterates on this until it loads cleanly — you review and approve, rather than write it from scratch.


How do I query IBM QRadar data in DuckDB?

dlt creates one table per resource. Query the loaded data with Python or SQL — or ask your agent to, through the MCP server's execute_sql_query tool.

Python (pandas DataFrame):

import dlt data = dlt.pipeline("ibm_qradar_pipeline").dataset() df = data.help_resources.df() print(df.head())

SQL:

SELECT * FROM ibm_qradar_data.help_resources LIMIT 10;

See querying your data with dataset and exploring it in marimo notebooks.


How do I deploy the IBM QRadar to DuckDB pipeline in production?

The pipeline runs locally, which is ideal for prototyping and one-off analysis. When you need it on a schedule, monitored on every load, and shared with your team, deploy the same dlt code on the dltHub platform — no infrastructure to maintain. The prompt above already ends with "run it on dltHub", so your agent can take it there directly.

  • Deploy & schedule — run the pipeline as a managed job with automatic retries.
  • Monitor — observable job queues, alerting, and load metrics for every run.
  • Transform — promote raw IBM QRadar loads into governed, documented models.
  • Visualize & share — explore data in notebooks and publish live dashboards instead of static screenshots.

Book a demo →


What other destinations can I load IBM QRadar data to?

dlt loads into any of these — only the destination argument changes:

DestinationExample value
PostgreSQL"postgres"
BigQuery"bigquery"
Snowflake"snowflake"
Redshift"redshift"
Databricks"databricks"
Filesystem (S3, GCS, Azure)"filesystem"

Set dlt.pipeline(destination="snowflake") and add credentials in .dlt/secrets.toml. On the dltHub platform the same pipeline runs against a managed Iceberg lakehouse. See the full destinations list.


Next steps

Was this page helpful?

Community Hub

Need more dlt context for IBM QRadar to DuckDB?

Request dlt skills, commands, AGENT.md files, and AI-native context.