IBM Support

QRadar : Unable to see events associated with an offense

Question & Answer


Question

Why am I not able to see events associated with an offense, especially when the number of associated events is high?
Consider an offense like the one displayed here (notice the high number of associated events):
 
image-20220406174144-1
When you click on the events hyperlink under Event/Flow count, an empty list is displayed:
image-20220406174425-2

Answer

An offense with high number of associated events is usually indicative of a rule that needs tuning. A high event count on an offense is not helpful for analysis. It also causes the magistrate to get heavily loaded and will manifest symptoms like these:
 
  • Inability to display events associated with an offense
  • No results when offenses are searched
  • SAR Sentinel notifications
  • Sluggish GUI when the Offense tab is clicked

The solution is to tune rules such that only meaningful events get associated with the offenses.

[{"Type":"MASTER","Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000cwthAAA","label":"Offenses"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]

Document Information

Modified date:
19 April 2022

UID

ibm16569931