IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Tracing the Offence magnitude change

    Posted Wed October 17, 2018 09:09 AM
    Hi All,

    Offence triggers on Qradar console with Auto calculated Magnitude. Later if no event flows to that offence or more events flows to that Offence, magnitude of that Offence changes. 
    Can i trace this activity in Qradar i.e At what time magnitude of Offence is changed?. If yes, could you please suggest how can i trace it.

    Example: Offence triggered in Qradar with magnitude 8. After one day, same offence magnitude is changed to 6. I want to know, at what time offence magnitude changed from 8 to 6.

    Regards,
    P.Raju

    ------------------------------
    P.Raju
    ------------------------------


  • 2.  RE: Tracing the Offence magnitude change

    Posted Sun January 20, 2019 12:00 AM
    Hi,
    I second this. My SOC teams desires this a lot. I guess through an App, we could grap the data with the API and keep tracks of all offenses. Maybe there's already something available in the x-force apps... let's have a look.

    Regards,

    ------------------------------
    Anthony Gayadeen
    ------------------------------