Exporting your analysis results to CSV

You can export the results of an incident investigation from QRadar® Advisor with Watson™ to CSV format.

About this task

After you submit an incident to Watson for investigation, you can export the results to CSV format. The CSV file contains all of the incident information that is included with the offense investigation.
Note: The current graph view that is showing is the view that is exported when you export to CSV format. For example, if the local graph is displayed and you export to CSV, you can specify your options and then the information from the local graph, with your specified options, is exported.

By exporting the results of your analysis, you can share the results with other groups to view the analysis in any CSV viewer. The CSV export contains information about malicious indicators such as toxicity, relevance, directionality, blocked and allowed flows and events, and reputation information.

Procedure

  1. Export to CSV format.
    • On the Relationship Graph page, click Export > Export to CSV.
    • On the Watson Investigation page, select one or more investigations and then click Export. On the Export Investigations page, click the CSV tab.
  2. Select the options that you want to include in the CSV file.
    Option Description
    Only malicious nodes Select to export malicious nodes only. Clear the checkbox if you want the exported CSV file to contain both malicious and non-malicious nodes.
    Only locally observed nodes Select to export malicious local nodes based on Watson enriched results. Clear the checkbox to export all malicious nodes.
    Headers Select to include headers for the columns in the exported CSV file.
    Columns Select the columns that you want to include in the exported CSV file.
    Indicator Types Specifies the populated list of the entity types that are returned by Watson.
    The following example shows the light theme UI:
    CSV Export Options screen
  3. Click Export.
  4. Download and save the file.
    An example of the format for the file is offenseid_stage_date.csv. Note: Multiple selections are downloaded and saved as a .zip file.