IBM Support

QRadar: Reports covering specific timeframe may not include all data due to table limitation settings

Troubleshooting


Problem

Reports for longer timeframes that exceed the result limit may not display all of the expected items.

Symptom

If a Log Activity search executed for the same period shows a greater number of events than is shown in for a Report configured on the same search, it may be due to the default limit of items in the report table.

Cause

When using the Report Wizard the default setting is Bar with 5 items limit only:
default_setting_in_report_wizard
When the Graph Type is changed to Table, then the limit stays the same, limiting the result set for the Report to less than the Saved Search might normally return.

Resolving The Problem

To increase the number of events/items displayed in the Report change the limit from 5 to any higher number.
report_wizard
The highest number is 65,000 items in the table, which is common for tables and spreadsheets and is the result of the fact that a 16-bit address space can address 216 locations. QRadar cannot exceed this value and in this case, there should be shortened the timeframe, to reduce the table size. 

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSV4BL","label":"IBM QRadar"},"ARM Category":[{"code":"a8m0z000000cwtmAAA","label":"Reports"}],"ARM Case Number":"TS013715421","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]

Document Information

Modified date:
29 July 2024

UID

ibm17161690