A task is set up to identify events that were missed by the Custom Rule Engine. Which two (2) types of events does an analyst look for?
To identify events that were missed by the Custom Rule Engine (CRE) in IBM Security QRadar SIEM, an analyst would primarily look for 'Log Only Events sent to a Data Store' and 'High Level Category Unknown Events.' Log Only Events are those that are stored directly without being processed by the CRE, indicating they might have been overlooked or not matched by any existing rules. High Level Category Unknown Events are those that do not fit into any of the predefined categories in QRadar, suggesting that the CRE might not have rules to handle or categorize these events properly. These types of events are crucial for analysts to review to ensure that no significant incidents are missed and to refine the rule set for better detection in the future.
Zack
10 months agoJulian
10 months agoAlberta
11 months agoCharlene
11 months agoCoral
10 months agoJanine
10 months agoMee
11 months agoAngelyn
11 months agoJeannetta
11 months agoMarisha
11 months agoAntonio
11 months agoMalissa
11 months agoRosalyn
10 months agoCrista
10 months ago