Skip to content

This scripts helps to analyze the rules in QRadar and identify those test that can cause performance problems.

Notifications You must be signed in to change notification settings

qradar-cafe/RuleAnalysis

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

5 Commits
 
 
 
 
 
 

Repository files navigation

Rule Analysis

This script has been developed to analyzise in a simple manner the rules in Qradar, in order to see posible options to increase the efficiency of the system

In order to get the rules, you just have to run this command in your QRadar:

/opt/qradar/support/extractRules.py -o reglas.tsv

The script has the "--help" option to see how to use it, but there is a small demo in the QRadar Cafe Monographic: https://community.ibm.com/community/user/security/viewdocument/2022-12-02-monografico-procedimien?CommunityKey=163246d9-12f0-424e-900e-018a512c0045&tab=librarydocuments

Analisis de Reglas

Este script se ha desarrollado para analizar de forma sencilla las reglas de QRadar y ver posibles fallos en su composición, o mejoras a hacer para incrementar la eficiencia.

Para obtener las reglas tan solo hay que obtenerlas mediante el comando:

/opt/qradar/support/extractRules.py -o reglas.tsv

El propio script tiene la opción "--help", para ver sus opciones, pero tenéis una demo de como usarlo en el Monográfico que realizamos en el QRadar Café: https://community.ibm.com/community/user/security/viewdocument/2022-12-02-monografico-procedimien?CommunityKey=163246d9-12f0-424e-900e-018a512c0045&tab=librarydocuments

About

This scripts helps to analyze the rules in QRadar and identify those test that can cause performance problems.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Contributors 2

  •  
  •  

Languages