Modifying event mapping
You can manually map a normalized or raw event to a high-level and low-level category (or QID).
Before you begin
This manual action is used to map unknown log source events to known QRadar events so that they can be categorized and processed appropriately.
About this task
For normalization purposes, QRadar automatically maps events from log sources to high- and low-level categories.
For more information about event categories, see the IBM QRadar Administration Guide.
If events are received from log sources that the system
is unable to categorize, then the events are categorized as unknown.
These events occur for several reasons, including:
- User-defined Events - Some log sources, such as Snort, allows you to create user-defined events.
- New Events or Older Events - Vendor log sources might update their software with maintenance releases to support new events that QRadar might not support.
Note: The Map Event icon is disabled for
events when the high-level category is SIM Audit or the log source
type is Simple Object Access Protocol (SOAP).