IBM QRadar

IBM QRadar

Join this online topic group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.


#Security
#QRadar
#SecuringhybridcloudandAI
 View Only

Offense Source Summary mis-match

  • 1.  Offense Source Summary mis-match

    Posted 08/13/20 11:35 AM
    Hello, 

    Actually I am facing an issue with an offense when it provide the summary. Below is a description. 

    We have recently enable a rule on our qradar appliance to monitor traffic to a specific destination and we have configure the rule to generate an offense whenever the destination is access. 
    In our active directory, we have a user (which I will call user 'abc') disable for the past months. 
    We have noticed when an active user (which I will call user 'xyz') has accessed the monitored destination and an offense is generated. In the Offense Source Summary in username we see user 'abc' which is disable on AD instead of user 'xyz'. 

    Has anyone face this issue before?
    What could be the possible root cause behind this?
    How can we solve this mismatching?

    Thanks

    ------------------------------
    Parvesh Dhurmea
    ------------------------------