Tracking expired user accounts

Use reference data collections to identify stale data, such as expired user accounts, in your IBM QRadar environment.

About this task

By default, reference data remains in QRadar until it is removed. However, when you create a reference data collection, you can configure QRadar to remove the data after a specified period of time.

When the data element expires, QRadar automatically deletes the value from the reference data collection and triggers an event to track the expiry.

Procedure

  1. Create a reference set to keep track of the time since a user last logged in.
    1. Set the Time to Live of elements to represent the period of time after which an unused user account is considered expired.
    2. Select the Since last seen button.
  2. Create a custom event rule to add login data, such as the username, to the reference set.
    Note: QRadar tracks the Date Last Seen for each data element. If no data is added for a particular user within the time-to-live period, the reference set element expires, and a Reference Data Expiry event is triggered. The event contains the reference set name and the username that is expired.
  3. Use the Log Activity tab to track the Reference Data Expiry events.

What to do next

Use the reference set data in searches, filters, rule test conditions, and rule responses.