How can an analyst search for all events that include the keyword "access"?
On the Offenses tab, which column explains the cause of the offense?
What type of custom property should be used when an analyst wants to combine extraction-based URLs, virus names, and secondary user names into a single property?
An analyst wishes to review an event which has a rules test against both event and flow data.
What kind of rule is this?
Which parameter should be used if a security analyst needs to filter events based on the time when they occurred on the endpoints?
What is the effect of toggling the Global/Local option to Global in a Custom Rule?
What does an analyst need to do before configuring the QRadar Use Case Manager app?
Offense chaining is based on which field that is specified in the rule?
For a rule containing the test "and when the source is located in this geographic location" to work properly, what must a QRadar analyst configure?
Which flow fields should be used to determine how long a session has been active on a network?