Hello,
Actually I am facing an issue with an offense when it provide the summary. Below is a description.
We have recently enable a rule on our qradar appliance to monitor traffic to a specific destination and we have configure the rule to generate an offense whenever the destination is access.
In our active directory, we have a user (which I will call user 'abc') disable for the past months.
We have noticed when an active user (which I will call user 'xyz') has accessed the monitored destination and an offense is generated. In the
Offense Source Summary in username we see user 'abc' which is disable on AD instead of user 'xyz'.
Has anyone face this issue before?
What could be the possible root cause behind this?
How can we solve this mismatching?
Thanks
------------------------------
Parvesh Dhurmea
------------------------------