IBM Security QRadar

 View Only
  • 1.  Qradar report

    Posted Mon April 08, 2019 12:47 PM
    hello everyone,

    I want to create a report in which i want to shows that inbound/outbound traffic to/from my network generated  for a specific country and this report need to be generated every 24 hours.

    i tried to generate the report on Qradar, First i add filter for that geographical then added some other filter such as firewall permit, tcp connection etc.Then i save search result, Ofcourcse in the result there were so many events.
    I generated report using this saved search but report not showing all content or sometime generated as blank page.  Can anyone provide suggestion.

    ------------------------------
    Mukesh Kumar
    ------------------------------


  • 2.  RE: Qradar report

    Posted Tue April 09, 2019 09:37 AM
    Have you tried generating the report by the hour? If so does data populate?

    ------------------------------
    Richard Gingras
    ------------------------------



  • 3.  RE: Qradar report

    Posted Tue April 09, 2019 11:41 AM
    Can u try to add a filter like  state geographic location = SomeLoc and give a try..

    ------------------------------
    Rama Subbaiah Dhara
    ------------------------------



  • 4.  RE: Qradar report

    Posted Wed April 10, 2019 07:58 AM
    Dear members

    My query get solved by adding following filters such as destination geographic country + logsource + byte received is greater than 1.
    Displayed this search via destination port.
    Then is showed this saved search in my report.

    ------------------------------
    Mukesh Kumar
    ------------------------------



  • 5.  RE: Qradar report

    Posted Thu December 02, 2021 09:37 AM
    how do you even filter a particular location? i tried inserting it with AQL but i don't get any results on any particular country.. i only get results when i input geographiclocation = 'other'.. can you please help me?

    ------------------------------
    Slavcho Andreevski
    ------------------------------