IBM Security QRadar

 View Only
  • 1.  Log of rules firing

    Posted Fri March 08, 2019 10:20 AM
    Greetings,
    Is there a log in QRadar that tracks the time and date a particular rule fired? We're looking to use this for metrics so that we can show the increase or reduction in the number of times a rule was activated.

    Thanks

    ------------------------------
    BrianBrehart
    ------------------------------


  • 2.  RE: Log of rules firing

    Posted Fri March 08, 2019 11:36 AM
    Hi Brian,

    When it comes to metrics on your top talking rules, would it help for you to create a report the top talking rules, and then add a trending chart to that data?

    ------------------------------
    DRAYTON GRAHAM
    ------------------------------



  • 3.  RE: Log of rules firing

    Posted Fri March 08, 2019 12:16 PM
    Drayton,

    It might at that. Do you have a recommendation as to how to make that go? 

    Thanks,
    Brian

    ------------------------------
    BrianBrehart
    ------------------------------



  • 4.  RE: Log of rules firing

    Posted Mon March 11, 2019 08:26 AM
    Another option would be to configure a rule response to dispatch a new event for any particular rule you wish to track.    You could then search and report on the dispatched events to analyze rule hit times, rates, trends, etc. 

    Thanks,
    Shannon Tompkins

    ------------------------------
    SHANNON TOMPKINS
    ------------------------------



  • 5.  RE: Log of rules firing

    Posted Tue March 12, 2019 04:25 PM
    You may want to use the SIEM Tuning Report (CRE event report) as a starting point.
    Look at about 36 minutes into the following (Tuning Methodology):
    QRadar Open Mic #24 Replay: Let's talk about Tuning QRadar (16 May 2017)
    YouTube remove preview
    QRadar Open Mic #24 Replay: Let's talk about Tuning QRadar (16 May 2017)
    This video provides a replay of IBM Security QRadar Open Mic #24: "Let's talk about Tuning QRadar" that was hosted on 16 May 2017. The presentation for this Open Mic is available as a PDF at http://ibm.co/2qsGhOJ - For your convenience, the following time stamps are provided...
    View this on YouTube >


    ------------------------------
    Kelly Abbott
    ------------------------------



  • 6.  RE: Log of rules firing

    Posted Wed March 13, 2019 04:41 PM
    Sorry I didn't get back sooner, but did that Open Mic help with what you were looking for?

    ------------------------------
    DRAYTON GRAHAM
    ------------------------------