Mapping custom properties

To enhance the offense analysis, you must map your IBM® QRadar® custom properties to the QRadar Advisor with Watson™ app property names.

Before you begin

You must have QRadar administrator privileges to map properties.

Starting with version 2.5.0, suggested property mapping are provided for you to add. For more information, see Mapping custom properties in V2.5.0 and later.

About this task

By configuring property mapping for event and flow data, your custom properties are mapped to standardized fields used in the engine that is running the analysis process.
Important: Only IP addresses that are not private and not marked as internal in QRadar network hierarchy, URLs, hashes, and domains are sent for cloud analysis. All other mappings affect only local data that is found in QRadar and never leave your network.
For the SourceIp & DestinationIp categories only IP custom properties are available for mapping. For all other categories, only AlphaNumeric properties are available for mapping. You must either convert AlphaNumeric properties to IP before they can be mapped or if you need to preserve the property type, you can copy it and make the copy an IP type.
Example: In the Custom Event Properties window of your QRadar Console, you can change the Field Type of custom property that belong in these categories. If you want to keep the Field Type of the custom property, you can copy the Field Type to a new custom property. In this example, if you want to map an AlphaNumeric custom property named "CustomSourceAddress" that contains both hostnames and IPs to the SourceIp category, you can create a new custom property named "CustomSourceIP" with the same definition as "CustomSourceAddress" but with a Field Type of IP. Only IPs will be included in the new custom property and it will be available for mapping in the Add Mapping section of the QRadar Advisor with Watson Admin Configuration.

Procedure

  1. On the navigation menu ( Navigation menu icon ), click Admin.
  2. In the Apps section, under QRadar Advisor with Watson, click Configuration.
  3. In the Property Mapping section, click Add Mapping.
  4. Select a type from the following list:
    • Flows
    • Events
  5. Select a canonical name from the list.
  6. Select a property from the list. The list is populated based on the canonical name you selected.
  7. Click Add.

Example

The following example shows V2.4.1 and earlier.
Property Mapping configuration

What to do next

Configure optional settings

Mapping custom properties in V2.5.0 and later

Map your custom properties to the QRadar Advisor with Watson app property names for a better analysis of your offenses.

About this task

In V2.5.0 and later, suggested properties are found based on your active log sources. Review the suggestions, add mappings for properties unique to your environment, and click Save properties to save these properties to your mappings.

Suggested Properties are discovered on the system when you first configure the Property Mapping screen. Results are cached for 15 minutes, and then, after that time, the suggested properties are updated when you return to the Configuration wizard. Tip: If anything changes in your environment in the future and new properties are discovered, you can return to the Property Mapping section in the Configuration wizard to review newly suggested properties and then save the properties.

Note: When you first configure the Property Mapping screen, you must review any suggested properties and then click Save properties before you can proceed to the next step. If no properties are suggested, then you can proceed without saving.

Procedure

  1. On the navigation menu ( Navigation menu icon ), click Admin.
  2. In the Apps section, under QRadar Advisor with Watson, click Configuration.
  3. In the Property Mapping section, review the suggested mappings or click Add custom property to add a new property mapping.
    1. In the Select a Source Type list, choose from Events or Flows.
    2. In the Select an Advisor Typelist, choose the type of QRadar Advisor with Watson property that you want to map to a QRadar property,
    3. In the Select a QRadar Propertylist, choose the QRadar property to map.
    4. Click Add.
    Add Mapping screen for V2.5.0
  4. Select Enabled if you want to use the mapped property.
  5. Click Save properties. Tip: You can no longer delete mappings, however, you can disable the mapping by clearing the Enabled checkbox.
    The following example shows V2.5.0 and later.
    Property mapping v2.5.0