Creating a URL categorization rule to monitor access to certain types of websites

You can create a rule that sends an email notification if users of the internal network access URL addresses that are categorized as gambling websites.

Before you begin

To use X-Force data in rules, your administrator must configure QRadar to load data from the X-Force servers.

To create a new rule, you must have the Offenses > Maintain Custom Rules permission.

Procedure

  1. Click the Offenses tab.
  2. On the navigation menu, click Rules.
  3. From the Actions list, select New Event Rule.
  4. Read the introductory text on the Rule wizard and click Next.
  5. Click Events and click Next.
  6. From the Test Group list box, select X-Force Tests.
  7. Click the plus (+) sign beside the when URL (custom) is categorized by X-Force as one of the following categories test.
  8. In the enter rule name here field in the Rule pane, type a unique name that you want to assign to this rule.
  9. From the list box, select Local or Global.
  10. Click the underlined configurable parameters to customize the variables of the test.
    1. Click URL (custom).
    2. Select the URL property that contains the URL that was extracted from the payload and click Submit.
    3. Click one of the following categories.
    4. Select Gambling / Lottery from the X-Force URL categories, click Add + and click Submit.
  11. To export the configured rule as a building block to use with other rules:
    1. Click Export as Building Block.
    2. Type a unique name for this building block.
    3. Click Save.
  12. On the Groups pane, select the check boxes of the groups to which you want to assign this rule.
  13. In the Notes field, type a note that you want to include for this rule, and click Next.
  14. On the Rule Responses page, click Email and type the email addresses that receive the notification.
  15. Click Next.
  16. If the rule is accurate, click Finish.