When the events from the sample_initiallog.txt file are received by QRadar, the Log Activity page displays them as of "unknown" type.
Log with "unknown" events
If the Log Activity page displays too many events that arrive from different devices, you can add an event filter. In this event filter, set KL_Threat_Feed_Service_v2
and KL_Verification_Tool
as the log sources (the operator used in the filter must be Equals any of
).
To correctly identify the events, set the mapping between QIDs and events:
KL_Threat_Feed_Service_v2
" in the Log Source column.
Stop the events flow
The event information will be displayed. The event name will be contained in Payload information.
Browsing event information
One result will be displayed in the Matching QIDs table.
Adding the correspondence between a QID and an event name
Log without "unknown" events