IBM QRadar SOAR

IBM QRadar SOAR

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Where is IBM SOAR storing incident records and how long will they be stored?

    Posted Mon July 22, 2024 10:45 PM

    Dear all, I have some questions about IBM SOAR:

    1. Where IBM SOAR storing incident records?
    2. What is maximum incident records can be stored and what if it reached ? (Retention by size)
    3. How long will incident records be stored ? (Retention by time) 

    Thanks and best regards.



    ------------------------------
    On Chi Thanh
    ------------------------------


  • 2.  RE: Where is IBM SOAR storing incident records and how long will they be stored?

    Posted Tue July 23, 2024 04:40 AM

    Hi On Chi Thanh,

    There are no fixed retention by size or time limits on the SOAR system.

    The data is stored in the DB, but in the case of the standalone appliance attachments are stored on the filesystem (on CP4S/Suite, the attachments are also in the DB).



    ------------------------------
    Martin Feeney
    Product Manager, IBM Security QRadar SOAR
    martin.feeney@ie.ibm.com
    ------------------------------



  • 3.  RE: Where is IBM SOAR storing incident records and how long will they be stored?

    Posted Wed July 24, 2024 12:04 AM

    Dear Martin,

    Thank you for your information,

    According to your answer, what is best practice to delete data of DB to prevent it exceed maximum threshold ?



    ------------------------------
    On Chi Thanh
    ------------------------------



  • 4.  RE: Where is IBM SOAR storing incident records and how long will they be stored?

    Posted Wed July 24, 2024 03:52 AM

    At the moment you can delete Incidents from the incident list, its a page at a time so the max would be 500.

    We are about to investigate improving that deletion logic so hoping we have a better solution in the not too distant future.



    ------------------------------
    Martin Feeney
    Product Manager, IBM Security QRadar SOAR
    martin.feeney@ie.ibm.com
    ------------------------------