This article explains how to create a routing rule to drop events that the user does not want store in QRadar®.
Drop" option alone are overruled by all other option of routing rule that target the same specific event. This situation can cause that the specific event is not drop as wanted.
- Log in as an administrator to QRadar.
- Click the Admin tab on the console.
- Click the Routing Rules icon.
- On the toolbar, click Add.
- In the new routing rule window, enter the following values for the event you want to drop:
- Name: A name that explains what the rule is about.
- Description: Add more context to the rule.
- Mode: Online, the Drop option is only available for Online mode.
- Data Source: Events.
- Event Filter: Select Event ID, Equals any of, and add the Event ID.
- Routing Options: Drop.
When you finish adding the information, click the Save button.
- If prompt, click Deploy Changes button.
ResultsAfter the deployment completes, the change is applied to all appliances. If you experience issues with routing rules or errors in the user interface, contact QRadar Support.
Was this topic helpful?
30 August 2022