Hi Jonathan
I ran the log search in log activity tab using filter (log source indexed-SIM2 Audit) and we are receiving logs like below,
User login,
User logout
Search executed
Search completed. etc. etc.
However in order to check the user-created or deleted in the last 6 months in Qradar, I used the filter as below,
Event Name is %PIX-0-502101
Event Name is any of %APF-6-USER_NAME_CREATED
Event Name is any of %PIX-0-502101
Log source is SIM Audit-2::console00046
However, I selected the duration as the last 6 months but no logs are showing. I tried searching for deleted user names as we deleted a few user names in last two months but it's not showing.
Regards
Asif Siddiqui
------------------------------
Asif Siddiqui
------------------------------
Original Message:
Sent: Fri July 26, 2019 10:04 AM
From: Jonathan Pechta
Subject: QRadar User Creation/Remove/Disable Dates
There is an internal log source that tracks changes in QRadar, called SIM Audit. You can add a filter and search for these log sources if you want. Our L3 team wrote an application to visualize the user activity in QRadar that is logged, called the QRadar Operations App. This might be an easy way to view audit activity by a certain user or view what admin might have deleted the user in question.
If you don't want to use an app, you can review the SIM Audit log source from the Log Activity tab. Filter > Log Source (Indexed) > SIM AUDIT-2. The payload will contain a timestamp in the Syslog Header for the event and it will also be logged in the Start Time in the event details page as well.
Not sure if this helps, but feel free to ask questions or if you run in to issues you can use the official support forum here: https://ibm.biz/qradarforums as this forum has more visibility for support and development team members.
------------------------------
Jonathan Pechta
QRadar Support Content Lead
Support forums: ibm.biz/qradarforums
jonathan.pechta1@ibm.com
Original Message:
Sent: Fri July 26, 2019 03:04 AM
From: Rabil Shah Karedia
Subject: QRadar User Creation/Remove/Disable Dates
Hi,
I would like to ask, How can we view the QRadar user creation/removal/deletion date-time information for audit perspective.
Version: QRadar 7.3.0
Thanks.
------------------------------
Rabil Shah Karedia
------------------------------