IBM Guardium Data Protection
IBM Guardium Data Protection is a comprehensive data security and compliance platform that provides real-time monitoring, auditing, and protection for sensitive data across databases, data warehouses, file systems, and big data environments. This enterprise-grade solution helps organizations discover, classify, and protect sensitive information while maintaining detailed audit trails for compliance and security investigations.
| Category | Vulnerability management |
| Direction | Query source |
| Sign-in | Username & Password |
| Query languages | STIX |
| Website | ibm.com |
Before you start
Huntbase signs in to IBM Guardium Data Protection with Username & Password. Create the credential in IBM Guardium Data Protection first, then keep it to hand for the Connect step.
- Log in to the CLI of the Guardium collector.
- Register an OAuth client by running
grdapi register_oauth_client client_id=<name> grant_types="password". - Copy the
client_secretvalue from the JSON output. - Choose the Guardium user whose username and password Huntbase will use.
- Quick search must be enabled and include "Policy violation", and active threat analytics must be enabled.
For the vendor's own instructions, see IBM Guardium REST API documentation.
Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.
Connect IBM Guardium Data Protection
- Go to Connections and click New connection, or click New connection on the IBM Guardium Data Protection product page.
- On Product, pick IBM Guardium Data Protection and choose the Owner.
- On Details, give the connection a Name and, optionally, a Description.
- On Connect, fill in the settings and credentials described below.
- On Verify, review the summary and click Create & check.
For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.
Settings
Where your IBM Guardium Data Protection lives:
| Field | Required | Notes |
|---|---|---|
| Server Address | Yes | Specify the IP address or hostname of the data source. |
| Port | Yes | The Guardium REST API port, usually 8443. Defaults to 8443. |
| Client ID | Yes | The client_id you passed to grdapi register_oauth_client. |
| Client Secret | Yes | The client_secret returned by grdapi register_oauth_client. |
| Self-Signed Cert (PEM) | No | Provide a self-signed or CA-signed certificate to securely communicate with the data source. |
Credentials
The only Method is Username & Password. Enter a Credential label (for example Production), then fill in:
| Field | Required | Notes |
|---|---|---|
| Username | Yes | Username with access to the search API. Secret — not shown again after you save it. |
| Password | Yes | Password of the user with access to the search API. Secret — not shown again after you save it. |
Query it
Once connected, IBM Guardium Data Protection can serve these languages in a query tab, and Scout can use it when you ask in Auto:
| Language | Use it for |
|---|---|
| STIX | STIX patterns for indicator sweeps, translated into the product's native search. |
Next steps
- Connections — health, credentials and settings after you connect
- Query languages — syntax, parameters and time ranges
- Chatting with Scout — ask questions without writing a query
- All integrations — the rest of the catalog