QRadar Searches
If you ever take a philosophical view on the technical aspect of Security Information and Event Management (SIEM), a fleeting thought is that SIEM is nothing but a very advanced search. Everything else is built to collect data, run correlation, run analytics, and then display the search in a better way. That is kind of true.
What we have learned and discussed so far is the way QRadar is deployed, its different components, how data is ingested, and so on. Now, we will start with using the ingested data to make sense of it. QRadar search is the most fundamental feature of QRadar. In this chapter, we will discuss QRadar searches and how we can optimize them and use them to the best that they can offer.
The following topics will be covered in this chapter:
- How do searches work?
- QRadar services involved in searches
- Different types of QRadar searches
- Concept of data accumulation
- Different ways to tune QRadar searches