IBM Support

QRadar: I can't select my Custom Event Property for a Routing Rule/Search or Report

Question & Answer


Question

I've created a Custom Event Property (CEP), but it's not available in the filters section to select when I create a Routing-/Rule or a Search or a Report.

Cause

Only optimised CEP's show up for Routing-/Rules etc.

Answer

  1. Open the CEP via Admin> Custom Event Properties
  2. Edit your newly created CEP.
  3. This checkbox has to be checked in the CEP:
    QRadar 7.3.2/7.3.3: Parse in advance for rules, reports, and searches
    QRadar 7.4.0/7.4.1: Enable for use in Rules, Forwarding Profiles and Search Indexing
  4. Click Save at the bottom-right of the window.
The CEP will be available for selection after a few minutes, when the optimising is completed.

[{"Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000cwsyAAA","label":"Admin Tasks"}],"ARM Case Number":"TS003594677","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Version(s)"}]

Document Information

Modified date:
28 August 2020

UID

ibm16208403