Including QRadar Network Insights data in searches

You can include IBM QRadar Network Insights content in your data searches by including the content fields in the search criteria.

Before you begin

To ensure that flow inspection is configured to capture the content that you want to use, see Configuring the flow inspection level.

About this task

To find the name of the QRadar Network Insights content fields that you can search for, see the basic inspection level and the enriched inspection level content tables.

The name of the content field that you want to search for might differ depending on whether you search by using a regular search or an advanced search. If you want to do a regular search, use the Query builder name from the content tables. To run an advanced search, use the Advanced Search name.

Procedure

  1. To include the data fields in a regular search, complete the following steps:
    1. On the Network Activity tab, click Search > New search.
    2. In the Column Definition section, the Available Columns list shows the QRadar Network Insights data that you can include in your search results.
    3. To include the column in your query results, select the column from the list and then click the arrow to move the column to the Columns list.
      Figure 1. Network Activity tab search view
      Shows the workflow to include specific columns in your search results.

    For more information about searching by using the query builder, see Creating searches.

  2. To include the data in an advanced search, follow these steps:
    1. On the Network Activity tab, click Advanced Search.
    2. In the Advanced Search box, type the Ariel Query Language (AQL) query that specifies the fields that you want and how you want to group them.

    For more information about creating advanced searches, see Advanced search options.

Results

The flows that match the search criteria appear on the Network Activity tab. To view more information about the flow, double-click it to open the Flow Information window.