IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only

Need to understand AQL query

  • 1.  Need to understand AQL query

    Posted Fri January 03, 2020 06:35 AM
    ​Hi All,

    I need to understand below AQL query,

    "SELECT "UrlHost" AS orig_value, domaintools::tldextract("UrlHost") AS domain_name ,REFERENCEMAP('dt_fqdn_to_domain',domain_name) AS domain FROM events WHERE "UrlHost" IS NOT NULL AND domain_name != '' AND domain_name!=domain AND LOGSOURCENAME(logsourceid) = 'WebProxy @ 127.0.0.1' LAST 5 MINUTES"



    Regards
    Asif Siddiqui

    ------------------------------
    asif siddiqui
    ------------------------------