Troubleshooting
Problem
Searching in QRadar® is more efficient when data is indexed. Systems that leverage indexes do not have to read through every piece of data to locate matches, as the index contains references to unique terms in the data and where the data is located. Since indexes use additional space on the disk, there is a trade-off between storage space and search time.
Resolving The Problem
Each article in this series discusses tips on how to improve search results in QRadar®.
- Part 1 - Utilize Quick Filters to Search Data
- Part 2 - Leveraging Indexed Properties in Search Queries
- Part 3 - Tips on Searching Data in QRadar
[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"Component":"Searches","Platform":[{"code":"PF016","label":"Linux"}],"Version":"All Versions","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]
Was this topic helpful?
Document Information
Modified date:
02 March 2021
UID
ibm10876344