IBM Support

QRadar: Regex Parsing Performance

How To


Summary

Regular expressions, or regex, are widely used in QRadar for data extraction, parsing, event correlation, and searching. When an event is received, QRadar uses regular expressions, in the custom event properties, to extract specific fields from the raw event data and map them to normalized event format. If the regular expression used is too complex, or inefficient, parsing is slow decreasing processing capacity. This behavior can lead to events waiting on persistent queue and routing to storage.

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000cwtiAAA","label":"Performance"}],"ARM Case Number":"","Platform":[{"code":"PF016","label":"Linux"}],"Version":"All Versions"}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
24 February 2023

UID

ibm16957752