IBM QRadar

IBM QRadar

Join this online topic group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.


#Security
#QRadar
#SecuringhybridcloudandAI
 View Only
  • 1.  Offense Investigations

    Posted 02/11/20 12:37 PM
    Hello,

    I need help in understanding the following from Qradar User guide:

    "Some events are created based on an incoming raw event, while others are created by the QRadar
    Custom Rule Engine (CRE). Events that are created by QRadar do not have a payload because they are not
    based on raw events."

    Thanks,
    PS



    ------------------------------
    prashant sharma
    ------------------------------


  • 2.  RE: Offense Investigations

    Posted 02/11/20 12:48 PM
    A log source will provide payloads, such as a Microsoft security log
    event where CRE is a rule fired creating a new event that was watching
    for a rule to be satisfied. Threat intel and firewall logs are great
    examples of these, a threat intel rule that fires against source IP is
    a matched CRE event, where the FW event containing the source IP is
    the log source incoming raw event payloaditself and represented in the
    payload. It is the difference between 'what log source says' vs QRadar
    rules as CRE or ADE matches.

    ------Original Message------

    Hello,

    I need help in understanding the following from Qradar User guide:

    "Some events are created based on an incoming raw event, while others are created by the QRadar
    Custom Rule Engine (CRE). Events that are created by QRadar do not have a payload because they are not
    based on raw events."

    Thanks,
    PS



    ------------------------------
    prashant sharma
    ------------------------------


  • 3.  RE: Offense Investigations

    Posted 02/12/20 03:06 AM
    Hi Prashant,

    CRE events are the rule events that is created by QRadar and analyzing of events sent by other log sources (Such as FW logs)
    CRE events does not have payload and it can be seen like below.

    UBA : Bruteforce Authentication Attempts senseValue=5

    You can see at least source IP, username etc information at payloads. But, CRE events does not contain these information. That's way "Events that are created by QRadar do not have a payload"



    ------------------------------
    Halil BALIM
    ------------------------------