Adding filters to improve search performance
When you search for event or flow information, you can improve performance by adding filters to search fields that are indexed.
About this task
The following table provides information about the fields that are indexed:
QRadar SIEM Tab | Indexed Filter |
---|---|
Log Activity tab (Events) | Username Source or Destination IP Destination Port Has Identity Device Type Device ID Category Matches Custom Rule |
Network Activity tab (Flows) | Application Source or Destination IP Destination Port |
Procedure
- Click the Log Activity tab, or the Network Activity tab.
- On the toolbar, click Add Filter.
- From the first list, select an index filter.
- From the second list, select the modifier that you want to use.
- Type or select the information for your filter. The controls that are displayed depend on the index filter that you added.
- Click Add Filter.