You can create a rule that sends an email notification
if users of the internal network access URL addresses that are categorized
as gambling websites.
Before you begin
To use X-Force data in rules, your
administrator must configure QRadar to load data from the X-Force servers.
To
create a new rule, you must have the permission.
Procedure
-
Click the Offenses tab.
-
On the navigation menu, click Rules.
-
From the Actions list, select New
Event Rule.
-
Read the introductory text on the Rule wizard and click Next.
-
Click Events and click Next.
-
From the Test Group list box, select X-Force
Tests.
-
Click the plus (+) sign beside the when URL (custom) is categorized by X-Force as
one of the following categories test.
-
In the enter rule name here field
in the Rule pane, type a unique name that you want to assign to this
rule.
-
From the list box, select Local or Global.
-
Click the underlined configurable parameters to customize
the variables of the test.
-
Click URL (custom).
-
Select the URL property that contains the URL that was
extracted from the payload and click Submit.
-
Click one of the following categories.
-
Select Gambling / Lottery from
the X-Force URL
categories, click Add + and click Submit.
-
To export the configured rule as a building block to use
with other rules:
-
Click Export as Building Block.
-
Type a unique name for this building block.
-
Click Save.
-
On the Groups pane, select the check boxes of the groups
to which you want to assign this rule.
-
In the Notes field, type a note
that you want to include for this rule, and click Next.
-
On the Rule Responses page, click Email and type
the email addresses that receive the notification.
-
Click Next.
-
If the rule is accurate, click Finish.