Use reference data collections to identify stale data, such as expired user accounts, in
your IBM
QRadar
environment.
About this task
By default, reference data remains in QRadar until it is removed.
However, when you create a reference data collection, you can configure QRadar to remove the data after a
specified period of time.
When the data element expires, QRadar automatically deletes the
value from the reference data collection and triggers an event to track the expiry.
Procedure
-
Create a reference set to keep track of the time since a user last logged in.
-
Set the Time to Live of elements to represent the period of time after
which an unused user account is considered expired.
-
Select the Since last seen button.
-
Create a custom event rule to add login data, such as the username, to the
reference set.
Note: QRadar tracks the
Date Last Seen for each data element. If no data is added for a particular
user within the time-to-live period, the reference set element expires, and a Reference
Data Expiry event is triggered. The event contains the reference set name and the
username that is expired.
-
Use the Log Activity tab to track the Reference Data
Expiry events.
What to do next
Use the reference set data in searches, filters, rule test conditions, and rule responses.