IBM Support

Investigating user behavior with QRadar Security Intelligence V2

Question & Answer


Question

In this lab, you learn how to use the User Behavior Analytics for QRadar (UBA) application to detect anomalous or malicious user behavior.

You can download UBA from the IBM Security App Exchange. QRadar UBA is already installed and configured in this lab. The following actions have been prepared:

  • A custom QRadar rule has been created
  • A custom QRadar rule to contribute to the user behavioral risk score by using the senseValue parameter has been added
  • The senseValue parameter has been tuned in a predefined UBA rule


Duration: 45 Minutes
Follow the link in related information to view the course on the IBM Security Learning Academy

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Version","Edition":" ","Line of Business":{"code":"LOB77","label":"Automation Platform"}}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
01 September 2022

UID

ibm16617629