IBM Support

QRadar: How to manage accumulated search results that are found in the Log activity tab under Managed Search Results

Question & Answer


Question

How can you manage large search result data on a daily basis?

Answer

Steps to manage Search Results:

    1. Log in to the QRadar User Interface.
    2. Open the Admin settings:
      1. In IBM Security QRadar V7.3.1, click the navigation menu , and then click Admin to open the Admin tab.
      2. In IBM Security QRadar V7.3.0 or earlier, click the Admin tab.
    3. Click on the System settings icon within the System Configuration section.
    4. Select the Ariel Database Settings in the left hand column to bring you to the appropriate settings.
    5. Change the Search Results Retention Period setting to the number of days, weeks, or months that are desired to retain the search results.

      Note: If you select 1 day, then after 24 hours from that time, your search results will be cleared for all users. The default is 1 day.


Results: You can now modify the default Search Results Retention Period.




Where do you find more information?




[{"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Admin Console","Platform":[{"code":"PF016","label":"Linux"}],"Version":"7.3.1;7.3;7.2.8;7.2","Edition":"All Editions","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
16 June 2018

UID

swg21903549