A task is set up to identify events that were missed by the Custom Rule Engine. Which two (2) types of events does an analyst look for?
To identify events that were missed by the Custom Rule Engine (CRE) in IBM Security QRadar SIEM, an analyst would primarily look for 'Log Only Events sent to a Data Store' and 'High Level Category Unknown Events.' Log Only Events are those that are stored directly without being processed by the CRE, indicating they might have been overlooked or not matched by any existing rules. High Level Category Unknown Events are those that do not fit into any of the predefined categories in QRadar, suggesting that the CRE might not have rules to handle or categorize these events properly. These types of events are crucial for analysts to review to ensure that no significant incidents are missed and to refine the rule set for better detection in the future.
Bethanie
9 months agoGilma
9 months agoEdna
10 months agoGary
10 months agoStacey
10 months agoMargret
10 months agoAdela
10 months agoBillye
11 months agoErnestine
11 months agoChandra
11 months agoPhuong
11 months agoJulie
11 months agoAntonio
11 months agoShantay
11 months agoMiesha
11 months agoSalome
11 months agoZack
2 years agoJulian
2 years agoAlberta
2 years agoCharlene
2 years agoCoral
2 years agoJanine
2 years agoMee
2 years agoAngelyn
2 years agoJeannetta
2 years agoMarisha
2 years agoAntonio
2 years agoMalissa
2 years agoRosalyn
2 years agoCrista
2 years ago