Another option would be to configure a rule response to dispatch a new event for any particular rule you wish to track. You could then search and report on the dispatched events to analyze rule hit times, rates, trends, etc.
Thanks,
Shannon Tompkins
------------------------------
SHANNON TOMPKINS
------------------------------
Original Message:
Sent: 03-08-2019 12:16 PM
From: Brian Brehart
Subject: Log of rules firing
Drayton,
It might at that. Do you have a recommendation as to how to make that go?
Thanks,
Brian
------------------------------
BrianBrehart
Original Message:
Sent: 03-08-2019 11:35 AM
From: DRAYTON GRAHAM
Subject: Log of rules firing
Hi Brian,
When it comes to metrics on your top talking rules, would it help for you to create a report the top talking rules, and then add a trending chart to that data?
------------------------------
DRAYTON GRAHAM
Original Message:
Sent: 03-08-2019 10:19 AM
From: Brian Brehart
Subject: Log of rules firing
Greetings,
Is there a log in QRadar that tracks the time and date a particular rule fired? We're looking to use this for metrics so that we can show the increase or reduction in the number of times a rule was activated.
Thanks
------------------------------
BrianBrehart
------------------------------