Hello, Davit. Thank you for the XML file! For anyone looking for a how-to video for Event Mapping in QRadar once you have the regex values in an XML, watch the following:
https://www.youtube.com/watch?v=gN7JMpbuAy0As for the Event Mappings values I used, they were as follows:
- Firewall Allow:
- Event Category = Allowed
- Event ID = Allow
- QID/Name = Firewall Permit - Event CRE
- Firewall Deny:
- Event Category = Denied
- Event ID = Deny
- QID/Name = Firewall Deny - Event CRE