Question & Answer
Question
How do I view all forensics query searched and recovered as I only see a subset of my available data?
Cause
The Forensics tab has a filter applied and the results displayed are the results that match the Query Filter, instead of all forensics documents available. To view 100% of the available documents, the user must clear the Query Filter.
Fig 1: A query filter was applied that returned 900 of 5,338 available documents.
Answer
- To reset your forensics query filter so you can view all recovered forensics data, click on query filter:
Fig 2: Location of the Query Filter icon in the user interface.
- Click on the + next to expand the ApplicationProtocol tree and clear the check box for the applied filter:
Fig 3: Note that there is no apply or save button, as all updates are saved immediately. Clear the check box to remove the applied filter.
- Double-click on Forensics tab to refresh and query view is displayed to verify the change.
Fig 4: Refresh the view of confirm the change. The top of the page should list the total number of filtered items versus available documents. - You should be able to view 100% (5,338 of 5,338) of all documents recovered by the forensics query.
Fig 5: The Query Filter has been cleared to display all available documents.
Related Information
[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSUK44","label":"IBM Security QRadar Incident Forensics"},"Component":"QRadar Incident Forensics;Forensics Recovery;Forensics search;Forensics query filter;Forensics query missing documents","Platform":[{"code":"PF016","label":"Linux"}],"Version":"All Versions","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]
Was this topic helpful?
Document Information
Modified date:
09 January 2019
UID
ibm10794143