QRadar Analyst Workflow
As we have seen in previous chapters, QRadar is a great security product that handles complex rules, collects different types of event and flow data, provides exceptional results in terms of performance, and helps with regulatory compliance. To enhance the user experience, QRadar Analyst Workflow provides an alternative user interface consisting of the following:
- Search view
- Pulse dashboards
- Offenses view
We will discuss these components in detail in the following sub-sections.
Important note
IBM QRadar Pulse is an app like any other. It is also part of QRadar Analyst Workflow. This was done as QRadar Analyst Workflow offers a much better user experience than the legacy user interface. Pulse is part of the new user experience.
Exploring the Search view
Analysts need to perform tasks such as event searches, and the Log Activity tab in QRadar Analyst Workflow provides multiple ways to run such searches. One of these is via Ariel...