Investigating offenses automatically
You can configure the QRadar® Advisor with Watson™ app to investigate offenses in QRadar automatically.
Before you begin
You must have QRadar administrator privileges to configure offenses for automatic investigation.
About this task
Starting with V2.5.2, if you don’t want to specify the criteria for auto-investigation of offenses, you can select the option to Investigate offenses suggested by Watson. Watson considers events and rules that triggered the offense, as well as other offense metadata, to predict the offenses that will most benefit from a full Watson investigation. It also learns from previous offense investigations. New offenses are pre-ranked by Watson and the offenses that benefit from a full Watson investigation are selected for auto-investigation. If none of the new offenses are chosen, then the latest offenses are selected for auto-investigation.