IBM QRadar

 View Only

 Guidance on notifications, email and network

Dariusz Nowak's profile image
Dariusz Nowak posted 01/20/25 08:23 AM

Hi All,

My first time so welcome to everyone!

I'm new in the Qradar world and have some questions, maybe somebody here can help!

1) How to adjust FROM email address for notifications - currently I'm stuck with qradar@localhost.localdomain causing some issues with my SPAM filters

2) Currently my notifications work via the custom 'Offense Rule' that action when 'New Offense is Created' and Severity is higher than X. I would like to use magnitude however can't see a filter on this. Am I blind or this is not possible? So email when the magnitude is 5 for example

3) How I can see what Network Hierarchy objects (ex. DMZ) or Reference Data (ex. Critical Assets) are used in my Rules?

Thanks
D

Rory Bray's profile image
Rory Bray

1) The from address can be set in the Admin tab -> System Settings. It's near the top "Alert Email from Address".  You may also find this useful https://www.ibm.com/docs/en/qsip/7.5?topic=notifications-configuring-event-flow-custom-email

2) There's no test for magnitude because it is a dynamically calculated attribute of the offense rather than an assigned one. It is made up of severity, credibility and relevance.  So you have to test for them individually.

3) really only by inference from the rules and events that contribute to the offense. You can search for events associated with an offense and from there aggregate on Networks. Or search by rule and find the events that hit a rule or BB that uses a certain reference data collection in its tests.

Dariusz Nowak's profile image
Dariusz Nowak

Amazing all 3 resolved 

Thank you!

D