IBM QRadar

IBM QRadar

Join this online topic group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  AQL Cheat Sheet

    Posted 02/03/20 01:31 PM
    Is there any available cheat sheet of most used AQL queries.

    ------------------------------
    Abdul Qudoos
    ------------------------------


  • 2.  RE: AQL Cheat Sheet

    Posted 02/03/20 10:58 PM

    Not sure what version of QRadar you are on, but the best cheat sheet is to use the new Show AQL button in QRadar 7.3.2 versions. This allows you to convert any query to view the AQL being run on the back end and understand how the search is run. You can then add QRadar apps or content packs that have searches and view the associated AQL query.

    Here are some links with examples:



    ------------------------------
    Jonathan Pechta
    QRadar Support Content Lead
    Support forums: ibm.biz/qradarforums
    jonathan.pechta1@ibm.com
    ------------------------------



  • 3.  RE: AQL Cheat Sheet

    Posted 02/04/20 03:34 AM
    If you prefer old-school PDFs, the PDF-based guides are in these locations:



    ------------------------------
    Darren H.
    ------------------------------