IBM Support

QRadar: Report to display log sources and total events per log source

Question & Answer


Question

How can I set up a weekly report that displays all of my log sources and total events per log source?

Answer

To create this report please do the following steps:

  1. Log in to the QRadar console

  2. Click the Reports tab

  3. Click Actions > Create



  4. Select Weekly as the schedule to generate the report

  5. Click Next


  6. Select the Layout you would like for the report



  7. Click Next

  8. Fill the Report Title field

  9. Select Events/Logs for the Chart Type



  10. Fill the Chart Title field



  11. Set Graph Type as Table



  12. Click Create New Event Search



  13. Scroll to the bottom and remove all the columns from the right except Event Count



  14. Add Log Source column to the Group By box

  15. Click Preview to verify that the search gives you the results you are requesting



  16. From the top of the search result click Save Criteria.



  17. Give the search a name and assign it to a Group.

  18. Click OK




  19. Click Save Container Details




  20. Click Finish

The report will take one week to present the data, if you need the report to present data immediately you need to select the report that you just created. Click Actions > Run Report on Raw Data.




Where do you find more information?

Related Information

[{"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"--","Platform":[{"code":"PF016","label":"Linux"}],"Version":"7.3.1;7.3;7.2.8","Edition":"Enterprise","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
16 June 2018

UID

swg21693695