Troubleshooting
Problem
When you create queries on the Forensics tab in QRadar Incident Forensics, spaces that are automatically added to Boolean searches might cause no results to be returned.
Symptom
When you run queries in the Recovery window, spaces are sometimes added both before and after brackets in Boolean search strings:
---- Case:mrsRestricted AND ( Collection10.10.10.10_Frost OR Collection:10.10.11.10_Frost OR Collection:10.11.10.10_Frost )
If you search on certain columns, such as WebCategory, no results are returned.
Also, when Boolean queries are added for columns that do display results, when you click next page, you might not see any search results.
Log InLog in to view more of this document
Was this topic helpful?
Document Information
Modified date:
16 June 2018
UID
swg21695480