Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IBM Exam C1000-156 Topic 4 Question 7 Discussion

Actual exam question for IBM's C1000-156 exam
Question #: 7
Topic #: 4
[All C1000-156 Questions]

What are some of the supported custom property expression types in QRadar?

Show Suggested Answer Hide Answer
Suggested Answer: B

IBM QRadar SIEM supports various types of custom property expressions to allow users to extract and parse data from logs in flexible and powerful ways. Among the supported custom property expression types, Regex, JSON, and LEEF are frequently utilized:

Regex (Regular Expressions): Regular expressions are a powerful tool used for pattern matching and extraction in text. In QRadar, regex can be used to create custom properties that parse specific patterns from log data, allowing for detailed and precise data extraction.

JSON (JavaScript Object Notation): JSON is a widely used data interchange format that is lightweight and easy to read and write. QRadar supports JSON expressions to parse and extract structured data from logs formatted in JSON.

LEEF (Log Event Extended Format): LEEF is a log format used by various devices to structure log data in a consistent manner. QRadar can utilize LEEF expressions to extract data from logs that use this format.

These types of expressions enhance QRadar's ability to handle diverse log formats and enable more accurate and efficient data analysis.

Reference IBM Security QRadar SIEM and IBM Security QRadar EDR integration.pdf


Contribute your Thoughts:

Lewis
1 years ago
I feel like I'm back in my database management class. RDBMS should definitely be an option here. I'm going with B, but with a bit of hesitation.
upvoted 0 times
Roslyn
1 years ago
I think Regex is crucial too. I'll choose D.
upvoted 0 times
...
Carlton
1 years ago
I agree, RDBMS is important. I'm going with A.
upvoted 0 times
...
...
Sheridan
1 years ago
Regex, JSON, and LEEF - that's the holy trinity of QRadar custom properties. B is the way to go, no doubt.
upvoted 0 times
...
Annamaria
1 years ago
Haha, HTML as a custom property expression type? What is this, a web design exam? Definitely going with B.
upvoted 0 times
Nan
12 months ago
B) Regex, JSON, LEEF
upvoted 0 times
...
Justine
12 months ago
Yeah, HTML does seem odd. B it is.
upvoted 0 times
...
Dwight
1 years ago
I agree, HTML seems out of place here. B does seem like the most logical choice.
upvoted 0 times
...
Ming
1 years ago
B) Regex, JSON, LEEF
upvoted 0 times
...
...
Whitney
1 years ago
I think the correct answer is D) Regex, JSON, HTML because those are commonly used in QRadar.
upvoted 0 times
...
Rodrigo
1 years ago
But I read somewhere that RDBMS is also supported.
upvoted 0 times
...
Avery
1 years ago
I'm a little iffy on the options here. Shouldn't RDBMS be one of the choices? I thought that was a core part of QRadar's capabilities.
upvoted 0 times
Benedict
1 years ago
I think the correct options are Regex, RDBMS, LEEF for supported custom property expression types in QRadar.
upvoted 0 times
...
Benedict
1 years ago
Yes, RDBMS is actually supported in QRadar for custom property expression types.
upvoted 0 times
...
...
Teri
1 years ago
I believe it's Regex, JSON, LEEF.
upvoted 0 times
...
Rodrigo
1 years ago
I think the supported custom property expression types in QRadar are Regex, RDBMS, LEEF.
upvoted 0 times
...
Berry
1 years ago
Option B seems the most accurate to me. Regex, JSON, and LEEF are definitely supported in QRadar.
upvoted 0 times
Chanel
1 years ago
I'm leaning towards option A. Regex and LEEF are supported, but I'm not sure about RDBMS.
upvoted 0 times
...
Refugia
1 years ago
I think option D might be a possibility too. Regex and JSON are definitely supported, but I'm not sure about HTML.
upvoted 0 times
...
Danica
1 years ago
I agree, option B is the correct one. Regex, JSON, and LEEF are indeed supported in QRadar.
upvoted 0 times
...
...

Save Cancel