How do searches work?
Though we have briefly discussed the idea of searching, let us dig deep into it and understand the mechanism of QRadar search.
Figure 6.1 – Components involved in a QRadar search
In the preceding figure, we have tried to cover all the QRadar components that are involved in a QRadar search. We can see a security analyst on the left-hand side trying to run a search on the QRadar Console Graphical User Interface (GUI). We can also see three Event Processors and one Flow Processor where data is stored. Then there are Data Node 1 and Data Node 2, which are attached to Event Processor 2. There are two Event Collectors, which are collecting logs, and those logs are stored on Event Processor 1. Similarly, flows are collected by QRadar Network Insights (QNI) and another Flow Collector (QFlow service) and are sent to the Flow Processor.
In the figure, we can see legends that are defined. The blue colored line depicts the search query...