Diagnosing The Problem
The existing EPS or Login failure searches or dashboard joins all internal CRE or EPS stats from the deployment. But even if you split it by Event Collector or Processor, you cannot allow the domain to read the System Notification log source because it is internal.
Resolving The Problem
The best approach is to create a search grouped by domain that counts events and create a dashboard of those events to get event count per minute or EPM.
To create a new search, perform the following steps:
- Log in to QRadar console as a tenant user.
- Navigate to the Log Activity tab.
- Click Log Activity tab.
- In the Advanced Search field, type the following AQL query:
SELECT DOMAINNAME(domainId) AS 'Domain', SUM("eventCount") as 'total' from events GROUP BY "domainId" order by 'total' desc last 1 MINUTES
Was this topic helpful?
30 April 2023