Event details toolbar

The events details toolbar provides several functions for viewing events detail.

The event details toolbar provides the following functions:

Table 1. Event details toolbar
Parameter Description
Return to Events List Click Return to Events List to return to the list of events.

Offense

Click Offense to display the offenses that are associated with the event.

Anomaly

Click Anomaly to display the saved search results that caused the anomaly detection rule to generate this event.

Note: This icon is only displayed if this event was generated by an anomaly detection rule.
Map Event Click Map Event to edit the event mapping. For more information, see Modifying event mapping.
False Positive Click False Positive to tune QRadar to prevent false positive events from generating into offenses.
Extract Property Click Extract Property to create a custom event property from the selected event.
Previous Click Previous to view the previous event in the event list.
Next Click Next to view the next event in the event list.
PCAP Data
Note: This option is only displayed if your QRadar Console is configured to integrate with the Juniper JunOS Platform DSM. For more information about managing PCAP data, see Managing PCAP data.
Print Click Print to print the event details.