Load IBM QRadar data to DuckDB
Build a IBM QRadar to DuckDB pipeline with your coding agent. One prompt scaffolds it with the dltHub AI harness, plus the IBM QRadar API base URL, auth, endpoints, and incremental loading.
IBM QRadar is a security information and event management platform providing a REST API to access, manage, and integrate with security data and configurations. Everything needed to build a working IBM QRadar → DuckDB pipeline is on this page: the API's base URL, authentication, endpoints, pagination and incremental field — plus a prompt that hands the whole job to your coding agent.
Build your IBM QRadar to DuckDB pipeline
Paste this prompt into Claude, Codex, or Cursor. The agent does the rest.
PromptRunuvx dlthub-init@latestto build a pipeline from IBM QRadar to DuckDB and run it on dltHub
That scaffolds a dltHub workspace and installs the dltHub AI harness — the project rules, the secrets-management skill, and the dlt MCP server your agent needs to work safely. From there it reads the IBM QRadar API, proposes the endpoints to load, then writes, runs and validates the pipeline while you review rather than type. Credentials are inspected through MCP tools, so your agent never reads secrets.toml itself. How the LLM-native workflow works →
Prefer to write it yourself? Every fact the agent uses is below.
IBM QRadar API at a glance
| Base URL | https://<console_ip>/api |
| Example endpoint | GET help/resources |
| Authentication | all requests require either an SEC header for tokens or an Authorization header for basic authentication — sent in the SEC header |
| Pagination | Not paginated |
| Incremental field | Range header parameter (paging) |
| API reference | https://www.ibm.com/docs/en/qradar-common?topic=api-endpoint-documentation-supported-versions |
These values come from the IBM QRadar API reference — the authoritative source if anything here looks out of date.
How do I authenticate with the IBM QRadar API?
Requests require an HTTP header for authentication; for authorized service tokens, use the 'SEC' header, and for username/password, use the standard 'Authorization' header with HTTP basic authentication.
1. Get your credentials
- Log into your IBM QRadar console. 2. Navigate to the Admin tab. 3. Under System Configuration, click User Management, then select Authorized Services. 4. Click Add Authorized Service. 5. Provide a name for the service, select a Security Profile, and assign a User Role (typically Admin). 6. Set an expiry date or choose 'No Expiry'. 7. Click Create Service. 8. In the Authorized Services Management window, select the newly created service and copy the token string from the Selected Token field. Note: The token is displayed only once; ensure you copy and save it securely before closing the window.
2. Add them to .dlt/secrets.toml
[sources.ibm_qradar_source] qradar_host = "your_qradar_console_ip_or_fqdn" sec_token = "your_authorized_service_token_here"
dlt reads this file automatically at runtime. With the harness, the setup-secrets skill prompts you for the values and never handles the raw credential in chat. For production, see setting up credentials with dlt.
What IBM QRadar data can I load into DuckDB?
These are the IBM QRadar endpoints dlt can load into DuckDB:
| Resource | Endpoint | Method | Data selector | Description |
|---|---|---|---|---|
| help_resources | /help/resources | GET | Retrieves a list of resource documentation objects. | |
| help_endpoints | /help/endpoints | GET | Retrieves a list of endpoint documentation objects. | |
| siem_offenses | /siem/offenses | GET | Retrieves a list of offenses. | |
| analytics_rule_groups | /analytics/rule_groups | GET | Retrieves a list of rule groups. | |
| ariel_databases | /ariel/databases | GET | Retrieves a list of Ariel databases. |
How do I load only new IBM QRadar records?
IBM QRadar exposes Range header parameter (paging) on help/resources, so dlt can request only the records that changed since the last run. Set it as the cursor_path and dlt tracks the high-water mark for you between runs.
{"name": "help_resources", "endpoint": { "path": "help/resources", "incremental": {"cursor_path": "Range header parameter (paging)", "initial_value": "2024-01-01T00:00:00Z"}, }}
On the first run dlt loads everything from initial_value; on every run after that it requests only what changed and appends with write_disposition="merge" if you set a primary key. See incremental loading.
What does the generated IBM QRadar pipeline look like?
A standard dlt REST API pipeline — the same code you would write by hand, loading /ariel/searches and /config/access/authorized_services from the IBM QRadar API into DuckDB:
import dlt from dlt.sources.rest_api import RESTAPIConfig, rest_api_resources @dlt.source def ibm_qradar_source(api_token=dlt.secrets.value): config: RESTAPIConfig = { "client": { "base_url": "https://<console_ip>/api", "auth": {"type": "api_key", "api_key": api_token, "name": "SEC"}, }, "resources": [ {"name": "help_resources", "endpoint": {"path": "help/resources"}}, {"name": "help_endpoints", "endpoint": {"path": "help/endpoints"}} ], } yield from rest_api_resources(config) def load_ibm_qradar_to_duckdb() -> None: pipeline = dlt.pipeline( pipeline_name="ibm_qradar_pipeline", destination="duckdb", dataset_name="ibm_qradar_data", ) load_info = pipeline.run(ibm_qradar_source()) print(load_info) if __name__ == "__main__": load_ibm_qradar_to_duckdb()
Run it with python ibm_qradar_pipeline.py. The agent iterates on this until it loads cleanly — you review and approve, rather than write it from scratch.
How do I query IBM QRadar data in DuckDB?
dlt creates one table per resource. Query the loaded data with Python or SQL — or ask your agent to, through the MCP server's execute_sql_query tool.
Python (pandas DataFrame):
import dlt data = dlt.pipeline("ibm_qradar_pipeline").dataset() df = data.help_resources.df() print(df.head())
SQL:
SELECT * FROM ibm_qradar_data.help_resources LIMIT 10;
See querying your data with dataset and exploring it in marimo notebooks.
How do I deploy the IBM QRadar to DuckDB pipeline in production?
The pipeline runs locally, which is ideal for prototyping and one-off analysis. When you need it on a schedule, monitored on every load, and shared with your team, deploy the same dlt code on the dltHub platform — no infrastructure to maintain. The prompt above already ends with "run it on dltHub", so your agent can take it there directly.
- Deploy & schedule — run the pipeline as a managed job with automatic retries.
- Monitor — observable job queues, alerting, and load metrics for every run.
- Transform — promote raw IBM QRadar loads into governed, documented models.
- Visualize & share — explore data in notebooks and publish live dashboards instead of static screenshots.
What other destinations can I load IBM QRadar data to?
dlt loads into any of these — only the destination argument changes:
| Destination | Example value |
|---|---|
| PostgreSQL | "postgres" |
| BigQuery | "bigquery" |
| Snowflake | "snowflake" |
| Redshift | "redshift" |
| Databricks | "databricks" |
| Filesystem (S3, GCS, Azure) | "filesystem" |
Set dlt.pipeline(destination="snowflake") and add credentials in .dlt/secrets.toml. On the dltHub platform the same pipeline runs against a managed Iceberg lakehouse. See the full destinations list.
Next steps
Was this page helpful?
Community Hub
Need more dlt context for IBM QRadar to DuckDB?
Request dlt skills, commands, AGENT.md files, and AI-native context.