Reports for longer timeframes that exceed the result limit may not display all of the expected items.
If a Log Activity search executed for the same period shows a greater number of events than is shown in for a Report configured on the same search, it may be due to the default limit of items in the report table.
When using the Report Wizard the default setting is Bar with 5 items limit only:
When the Graph Type is changed to Table, then the limit stays the same, limiting the result set for the Report to less than the Saved Search might normally return.
Resolving The Problem
To increase the number of events/items displayed in the Report change the limit from 5 to any higher number.
The highest number is 65,000 items in the table, which is common for tables and spreadsheets and is the result of the fact that a 16-bit address space can address 216 locations. QRadar cannot exceed this value and in this case, there should be shortened the timeframe, to reduce the table size.
Document Location
[{"Type":"MASTER","Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSV4BL","label":"IBM QRadar"},"ARM Category":[{"code":"a8m0z000000cwtmAAA","label":"Reports"}],"ARM Case Number":"TS013715421","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]
Was this topic helpful?
Document Information
Modified date:
29 July 2024