Event details toolbar
The events details toolbar provides several functions for viewing events detail.
The event details toolbar provides the following functions:
| Parameter | Description |
|---|---|
| Return to Events List | Click Return to Events List to return to the list of events. |
Offense |
Click Offense to display the offenses that are associated with the event. |
Anomaly |
Click Anomaly to display the saved search results that caused the anomaly detection rule to generate this event. Note: This
icon is only displayed if this event was generated by an anomaly detection
rule.
|
| Map Event | Click Map Event to edit the event mapping. For more information, see Modifying event mapping. |
| False Positive | Click False Positive to tune QRadar to prevent false positive events from generating into offenses. |
| Extract Property | Click Extract Property to create a custom event property from the selected event. |
| Previous | Click Previous to view the previous event in the event list. |
| Next | Click Next to view the next event in the event list. |
| PCAP Data | Note: This option is only displayed if your QRadar Console
is configured to integrate with the Juniper JunOS Platform DSM. For
more information about managing PCAP data, see Managing PCAP
data.
|
| Click Print to print the event details. |