IBM Support

QRadar: Report to display log sources and total events per log source

Question & Answer


How can I set up a weekly report that displays all of my log sources and total events per log source?


To create this report please do the following steps:

  1. Log in to the QRadar console

  2. Click the Reports tab

  3. Click Actions > Create

  4. Select Weekly as the schedule to generate the report

  5. Click Next

  6. Select the Layout you would like for the report

  7. Click Next

  8. Fill the Report Title field

  9. Select Events/Logs for the Chart Type

  10. Fill the Chart Title field

  11. Set Graph Type as Table

  12. Click Create New Event Search

  13. Scroll to the bottom and remove all the columns from the right except Event Count

  14. Add Log Source column to the Group By box

  15. Click Preview to verify that the search gives you the results you are requesting

  16. From the top of the search result click Save Criteria.

  17. Give the search a name and assign it to a Group.

  18. Click OK

  19. Click Save Container Details

  20. Click Finish

The report will take one week to present the data, if you need the report to present data immediately you need to select the report that you just created. Click Actions > Run Report on Raw Data.

Where do you find more information?

Related Information

[{"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"--","Platform":[{"code":"PF016","label":"Linux"}],"Version":"7.3.1;7.3;7.2.8","Edition":"Enterprise","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
16 June 2018