IBM Developer

Article

Transform plain language queries with AQL CodeGen and watsonx

Generate an AQL statement from a plain English query

By Honey Gidwani, Divya Kamath, Rahul K P
Archived content

Archive date: 2026-01-04

This content is no longer being updated or maintained. The content is provided “as is.” Given the rapid evolution of technology, some content, steps, or illustrations may have changed.

In today's rapidly evolving cybersecurity landscape, effective threat detection and incident response are crucial. Using AI for cybersecurity is now essential for enhancing IT security performance at an enterprise level. AI provides analysis and threat identification to help security professionals minimize breach risk, prioritize risks, direct incident response, and identify malware attacks before they occur.

Generative AI use for cybersecurity purposes is growing rapidly. Generative AI can play a multifaceted role, revolutionizing traditional defence mechanisms and augmenting the capabilities of cybersecurity professionals.

The AQL CodeGen app simplifies tasks for cybersecurity professionals who require rapid and accurate data retrieval and need to gain insights to help keep systems and data secure. Crafting complex Ariel Query Language (AQL) statements can be challenging, particularly for non-technical staff. AQL CodeGen uses smart AI and the IBM watsonx platform to understand plain language requests and generate the right queries for IBM QRadar users.

Component technologies

The AQL CodeGen app is built using the following software:

QRadar SIEM

IBM QRadar SIEM is a market-leading Security Information and Event Management (SIEM) solution that creates prioritized, high-fidelity alerts in real time by correlating analytics, threat intelligence, and network and user behavior anomalies to help security analysts stay focused on investigating and remediating the right threats. QRadar SIEM helps you quickly catch and remediate threats.

With QRadar SIEM, security teams can take advantage of the following features:

  • Prioritized, high-fidelity alerts in real time to detect targeted threats
  • Fully integrated Network Detection and Response (NDR) for monitoring network flows anchored to an event or log data
  • 700+ integrations for proactive detection and response with a broad range of tightly integrated add-on offerings
  • 1,500 out-of-the-box use cases aligned to MITRE ATT&CK to quickly identify and correlate activities throughout the kill chain with end-to-end visibility
  • Intuitive, automatic query builder built-in with smart property detection to quickly search and pinpoint valuable data without writing rules and code.

Ariel Query Language

The Ariel Query Language is a structured query language that you use to communicate with Ariel databases. The Ariel database in IBM QRadar SIEM stores event and flow data. It’s a read-only, non-relational database that’s created minute by minute. You use AQL to query and manipulate event and flow data from the Ariel database.

watsonx.ai

IBM watsonx.ai is IBM's enterprise studio for AI builders to train, validate, tune, and deploy both traditional machine learning and new generative AI capabilities powered by foundation models. This platform combines best-of-breed architectures with a focus on data acquisition, provenance, and quality, to serve enterprise needs. It expedites the development of AI applications while requiring less data and significantly reducing the manual effort involved.

A primary feature of watsonx.ai is its utilization of generative AI, which can produce various types of content. It supports a collection of open source and IBM foundation models that you can prompt to obtain a result. All these foundation models support a range of use cases for both natural languages and programming languages.

The ibm/granite-20b-code-instruct model in the watsonx.ai library has been leveraged to generate AQL queries, with suitable prompts. This 20 billion-parameter model provides code recommendations based on natural language requests, saving time and resources compared to manual coding efforts.

Challenges in SIEM querying

Following are some specific challenges in SIEM querying that the AQL CodeGen app can help you overcome:

  • Complex syntax: Writing AQL queries requires a solid understanding of the language's syntax, making it inaccessible to non-technical team members and hindering quick threat response.
  • Language barrier: Not all security analysts are proficient in AQL, creating a language barrier that slows down the process of deriving insights from security data.
  • Time commitment: Crafting precise AQL queries is time-consuming, and in the fast-paced world of cybersecurity, every moment counts.

AQL CodeGen benefits

The AQL CodeGen app helps you solve the main SIEM querying challenges.

  • Accessibility: It democratizes the power of AQL by allowing cybersecurity professionals to communicate their requirements in plain English, enabling a broader range of team members to effectively utilize SIEM systems.
  • Efficiency: The app significantly reduces the time it takes to construct AQL queries, enhancing the speed of threat detection and incident response.
  • Accuracy: By converting English-language requests into AQL statements, the app minimizes the risk of query errors, ensuring that security analysts obtain accurate results.

AQL CodeGen workflow

So, how do you use AQL CodeGen? Following is a typical work progression to unlock the app’s value:

  1. Express queries in plain English: Simply articulate your data queries using plain English language.
  2. Automatically generate an AQL statement: AQL CodeGen initiates an API call to watsonx, utilizing advanced language models, to transform the plain English query into an Ariel Query Language (AQL) statement. The app then processes the response from watsonx, automatically generating a precise AQL statement.
  3. Test the AQL statement: AQL CodeGen has an integrated test function within its UI, enabling you to identify any errors or syntax issues in your current AQL statement.
  4. Search data effortlessly: The app seamlessly redirects to the Log/Network Activity tab to display results for the analyst.

AQL CodeGen demo

To see how AQL CodeGen works in the real world, watch the following demo video:

Installing AQL CodeGen

AQL CodeGen is stored as a GitHub repository. To view the installation instructions, download the app, and install to IBM QRadar, go to the following GitHub repository:

Summary

In this article, you’ve been introduced to AQL CodeGen, an app that helps you integrate generative AI into your security workflow. You’ve seen how AQL CodeGen can transform the way you and your colleagues interact with IBM QRadar SIEM and how it can improve the speed, efficiency, and accuracy of your cybersecurity processes.

Next steps

To learn more about the AQL CodeGen app and IBM’s cybersecurity platform, see the following resources: