QRadar: Difference between disabling and deleting a QRadar log source

What is the difference between disabling and deleting a QRadar log source?


Disabled and deleted are logical functions, and the following points explain difference between them.
Disabling a log source
  • When a log source is disabled from QRadar, the log source remains visible in the Log Source Management (app). image1
  • You can see the log source in LSM App and also be able to search data associated with a disabled log source.
  • Whether the disabled log source is capable of auto-discovery or not, it is not re-created automatically since it exists.
  • If you remove a log source, then any search or rule that references to this particular log source eventually breaks.
Deleting a log source
  • When a log source is deleted from QRadar, the log source is not visible in Log Source Management (app).
  • You cannot see the “Add filter” list to search for the data that is associated with the deleted log source.
  • If the deleted log source is capable of auto-discovery, then after deleting, it is again re-created automatically.
Note: We recommend disabling a log source rather than deleting a log source.

    Modified date:
    28 March 2023