On the Log Activity tab in QRadar. what are the options available when right-clicking an IP address of an event to access more event filter information?
A.
Filter on. False Positive. More Options. Quick Filter
B.
Filter out, False Negative, More Options, Quick Filter
C.
Filter off, True Positive, Less Options, Quick Search
D.
Filter in, True Negative, Less Options. Quick Search
When you right-click on an IP address within an event in the QRadar Log Activity tab, you get a context-sensitive menu with these primary options:
Filter on: This is the main way to focus your view. It adds the selected IP address as a filter, showing you only events associated with that IP.
False Positive: Marking an event as a false positive helps QRadar's analytical engine learn and potentially reduce similar alerts in the future.
More Options: This expands the menu to show further actions you might take on the event such as:
Adding the IP to a reference set
Running an AQL query
Executing a custom action
Searching in other areas of QRadar using the IP address.
Quick Filter: Provides a quick, inline way to add additional filtering logic based on other fields of the event.
References:
IBM QRadar Log Activity Tab Overview: This section of the QRadar documentation describes the actions available in the Log Activity tab: https://www.ibm.com/docs/SSKMKU/com.ibm.qradar.doc/c_qradar_log_activ_tab_over
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit