Beruflich Dokumente
Kultur Dokumente
2
Source/Destination Network filters allow the filtering of traffic
where clients are connecting to hosts on another network.
Note: This could also be accomplished with the Flow Direction filter of
L2R
3
• Combining multiple filters can help find inappropriate
traffic.
4
Scenario: Applications not running on the correct port
Actions:
• Filter on applications (e.g. HTTP) using Application is
Web
• Alternative filters:
• „Source Port Does not equal 80‟
• „Source or Destination Port Does not equal 80‟
5
Scenario: Search for large amounts of data leaving the network
Action: Use Direction (L2R) and Byte Count (SRC Bytes >)
6
Notes:
7
1. Display: Default shows standard time series view Default
(Normalized)
8
• If there is accumulated data for a Search the accumulated data will be
queried first, detailed data second
• QRadar also does ‘minute, hour and day’ roll ups making
displaying time series data more efficient. (e.g. 1 hour and 1
day intervals)
• To grab more data execute the query for a longer time period
9
Requested Time Accumulated Resolution
Period Data Displayed
≤ 1 hour 1 Day 1 minute
Notes:
10
Time Series Chart Scenarios:
Scenario 1
User wants to plot a single item over time on the graph (e.g. total bytes
for a single application)
Time Series Configuration
1. Create search for specific application
2. Make sure column for bytes (set to sum) is in column list
3. Group by the parameter being searched (e.g. application)
4. This ensures only a single row will be included in search results, so
this is the only data that will get accumulated
Scenario 2
Users wants to plot multiple specific items over time (e.g. total number
of events per interval for 10 specific categories for a group of devices)
Time Series Configuration
1. Create search which includes specific categories and specific devices
2. Group by Categories
3. Make sure Top N number configured in chart covers total number of
categories (up to 50 objects can be displayed)
Scenario 3
Users wants to Graph Top IPs for all traffic over time.
Time Series Configuration
1. No search criteria required
2. Group by IP
3. Set Top N to desired number
11
• As an log events or flow events match a building block or rule those events are tagged with
that rule.
• Filter in the Activity interfaces to search for these events (very useful for creating reports)
• Group of rules called Category Definitions as a number of very useful filters
12
• When investigating offenses it is often useful to group all events by “Matched Rules”
• Can also be used as a information source for tuning
13
• Apply filters to get to the information
14
Questions and Notes:
15