IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only

Use Asset Profiler-2 logs in rules

  • 1.  Use Asset Profiler-2 logs in rules

    Posted Sun April 25, 2021 06:44 AM
    Hi! Can you help with question, can events from asset profiler-2 be used in custom rules? We parse some fields (such as hostname and IP) from Hostname created and IP created events and want using its custom fields in our rules, add this data to reference set. But data not add to our referense set from created rule. May be this log source cant be used for it? Can log source asset profiler-2 will be used in this way?

    ------------------------------
    Serhii Barabash
    ------------------------------