IBM Support

Searching Your QRadar Data Efficiently: Start

Troubleshooting


Problem

Searching in QRadar® is more efficient when data is indexed. Systems that leverage indexes do not have to read through every piece of data to locate matches, as the index  contains references to unique terms in the data and where the data is located. Since indexes use additional space on the disk, there is a trade-off between storage space and search time.

Resolving The Problem

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"Component":"Searches","Platform":[{"code":"PF016","label":"Linux"}],"Version":"All Versions","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
02 March 2021

UID

ibm10876344