A log source will provide payloads, such as a Microsoft security log
event where CRE is a rule fired creating a new event that was watching
for a rule to be satisfied. Threat intel and firewall logs are great
examples of these, a threat intel rule that fires against source IP is
a matched CRE event, where the FW event containing the source IP is
the log source incoming raw event payloaditself and represented in the
payload. It is the difference between 'what log source says' vs QRadar
rules as CRE or ADE matches.
------Original Message------
Hello,
I need help in understanding the following from Qradar User guide:
"Some events are created based on an incoming raw event, while others are created by the QRadar
Custom Rule Engine (CRE). Events that are created by QRadar do not have a payload because they are not
based on raw events."
Thanks,
PS
------------------------------
prashant sharma
------------------------------