Reference data collections and custom rules PDF
Reference data collections and custom rules PDF
IBM may not offer the products, services, or features discussed in this document in other countries. Consult your local IBM representative
for information on the products and services currently available in your area. Any reference to an IBM product, program, or service is not
intended to state or imply that only that IBM product, program, or service may be used. Any functionally equivalent product, program, or
service that does not infringe any IBM intellectual property right may be used instead. However, it is the user’s responsibility to evaluate
and verify the operation of any non-IBM product, program, or service.
IBM may have patents or pending patent applications covering subject matter described in this document. The furnishing of this document
does not grant you any license to these patents. You can send license inquiries, in writing, to:
The following paragraph does not apply to the United Kingdom or any other country where such provisions are inconsistent with locallaw:
INTERNATIONAL BUSINESS MACHINES CORPORATION PROVIDES THIS PUBLICATION “AS IS” WITHOUT WARRANTY OF ANY KIND,
EITHER EXPRESS OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF NON-INFRINGEMENT,
MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. Some states do not allow disclaimer of express or implied warranties in
certain transactions, therefore, this statement may not apply to you.
This information could include technical inaccuracies or typographical errors. Changes are periodically made to the information herein; these
changes will be incorporated in new editions of the publication. IBM may make improvements and/or changes in the product(s) and/or the
program(s) described in this publication at any time without notice.
Any references in this information to non-IBM websites are provided for convenience only and do not in any manner serve as an
endorsement of those websites. The materials at those websites are not part of the materials for this IBM product and use of those
websites is at your own risk.
IBM may use or distribute any of the information you supply in any way it believes appropriate without incurring any obligation to you.
Information concerning non-IBM products was obtained from the suppliers of those products, their published announcements or other
publicly available sources. IBM has not tested those products and cannot confirm the accuracy of performance, compatibility or any other
claims related to non-IBM products. Questions on the capabilities of non-IBM products should be addressed to the suppliers of those
products.
This information contains examples of data and reports used in daily business operations. To illustrate them as completely as possible, the
examples include the names of individuals, companies, brands, and products. All names and references for organizations and other business
institutions used in this deliverable’s scenarios are fictional. Any match with real organizations or institutions is coincidental.All names and
associated information for people in this deliverable’s scenarios are fictional. Any match with a real person is coincidental.
TRADEMARKS
IBM, the IBM logo, and ibm.com are trademarks or registered trademarks of International Business Machines Corp., registered in many
jurisdictions worldwide. Other product and service names might be trademarks of IBM or other companies. A current list of IBM
trademarks is available on the web at “Copyright and trademark information” at www.ibm.com/legal/copytrade.shtml.
Adobe, the Adobe logo, PostScript, and the PostScript logo are either registered trademarks or trademarks of Adobe SystemsIncorporated
in the United States, and/or other countries.
Java and all Java-based trademarks and logos are trademarks or registered trademarks of Oracle and/or its affiliates.
The registered trademark Linux® is used pursuant to a sublicense from the Linux Foundation, the exclusive licensee of Linus Torvalds,
owner of the mark on a worldwide basis.
Microsoft, Windows, Windows NT, and the Windows logo are trademarks of Microsoft Corporation in the United States, other countries, or
both.
UNIX is a registered trademark of The Open Group in the United States and other countries.
VMware, the VMware logo, VMware Cloud Foundation, VMware Cloud Foundation Service, VMware vCenter Server, and VMware vSphere
are registered trademarks or trademarks of VMware, Inc. or its subsidiaries in the United States and/or other jurisdictions.
Red Hat®, JBoss®, OpenShift®, Fedora®, Hibernate®, Ansible®, CloudForms®, RHCA®, RHCE®, RHCSA®, Ceph®, and Gluster® are trademarks or
registered trademarks of Red Hat, Inc. or its subsidiaries in the United States and other countries.
© Copyright International Business Machines Corporation 2022.
This document may not be reproduced in whole or in part without the prior written permission of IBM.
US Government Users Restricted Rights – Use, duplication or disclosure restricted by GSA ADP Schedule Contract with IBM Corp.
Contents
Course materials may not be reproduced in whole or in part without the prior written permission of IBM. 1
Exercise 1 Creating reference data collections
Course materials may not be reproduced in whole or in part without the prior written permission of IBM. 2
Exercise 1 Creating reference data collections
Note: When you leave the Time to Live field blank, the parameter is set to Forever.
8. In the Key Label field, double-click text to highlight, press backspace to delete, and type
Emp_name.
9. Unless otherwise stated, keep the Default Key Type as ALN (alphanumeric).
3 .
Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Exercise 1 Creating reference data collections
12. Click Add Inner Key. Double-click text to highlight, press Backspace, then type badge_status.
In the next steps, you add elements to the reference table by using different methods. Press Tab to
move to the next text field for steps 16, 17, 18.
4
Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Exercise 1 Creating reference data collections
20. Review the data of the element that you added by expanding the Key entry Susan Cameron.
21. Scroll down using the down arrow key or the scroll bar to see the entire entry.
5
Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Exercise 1 Creating reference data collections
23. Double-click Import Files folder and double-click the Emp_badges.csv file.
Note: The first line contains the header keys. The remaining lines follow the structure: Parent
Key, Inner Key, Value. The values are separated by commas.
25. Close the import file and then close the Documents window.
26. Back in the Reference Data Management app, click Import from File.
6
Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Exercise 1 Creating reference data collections
28. Double-click the Import_files folder, select the import file that you examined, and click Open.
7
Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Exercise 1 Creating reference data collections
30. Observe the additional entries for Anthony Pease and Eric Williams.
31. Expand the Reference Set section and click Create New.
34. For Time to Live, click “days.” From the drop-down list, select mons.
Important: You set the Time to Live value to 2 months since last seen. When the data element
expires, QRadar automatically deletes the value from the reference data collection and triggers
an event to track the expiration.
8
Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Exercise 1 Creating reference data collections
9
Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Exercise 2 Creating a custom rule
1. Double-click Offenses.
2. Click Rules.
4. To get to the Rule Test Stack Editor in the Rule wizard, click Next twice.
10
Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Exercise 2 Creating a custom rule
6. To select the second test group from the top, click the + icon.
9. Click Add.
11
Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Exercise 2 Creating a custom rule
Hint: With this rule test, you ensure that only events that are from the log source type Physical
Access are tested any further. This criteria makes the rule less expensive and saves system
resources.
12. In the Test Group search window, double-click the existing text to highlight, press the backspace key,
then type ref.
13. To select the last test group that contains “Reference Table”, click the + icon.
14. Click Reference Table Key, select Employee badges -> Emp name from the drop-down list and
click Submit.
15. Click any selected event properties and search for Username. Select it from the list and click the
Add+ button. Then click Submit.
12
Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Exercise 2 Creating a custom rule
17. Select badge_status from the drop-down list and click Submit.
18. Click operator and then click Submit to choose the default entry of equals.
19. Click selected event property and type expired in the lower text field as a value to compare
against.
21. Confirm that your rule tests look like this image.
24. Click the Ensure the detected event is part of an offense checkbox and from the drop-down list,
scroll down by using the down arrow key or scroll bar to select Username.
13
Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Exercise 2 Creating a custom rule
Note: This Rule Action sets the severity of the event that matches all rule tests to 8. Then, it
checks whether this event is part of an offense that is indexed on the Username. If no offense
exists yet, a new offense is created. So, the first event that matches the tests fires the rule and
creates the offense. All other events are assigned to the rule.
25. Check the Dispatch New Event checkbox and type Badge expired for the Event Name, and
User badge expired for the Event Description.
26. Change the Severity under Event details to 8, and the credibility and Relevance to 0.
27. Check Ensure the dispatched event is part of an offense and use the drop-down arrow to select
Username. You must scroll down using the down arrow key or scrollbar.
28. Check Add to a Reference Set and from the drop-down list in the first field, choose Username
(you must scroll down) and from the second drop-down list, choose
Employee_badge_expired-Alphanumeric.
14
Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Exercise 2 Creating a custom rule
Note: The first entry of the Rule Response dispatches a new event for the purpose of
documentation and assigns it to an offense that is indexed on Username. This offense is the one
that is already created in the Rule action. The second entry in the Rule Response adds the
Username to the reference set Employee_badge_expired. When the element expires, an
expiration event is dispatched from the system.
29. Scroll to the bottom to make sure that Enable this rule if you want to begin watching events
right away is selected.
It is selected by default.
15
Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Exercise 3 Testing the rule
Hint: Sometimes the red dot does not appear immediately. Click the Pause button or select last
5 min in the View options.
16
Course materials may not be reproduced in whole or in part without the prior written permission of IBM.
Exercise 3 Testing the rule
Note: Notice that 2 events are assigned to this offense. One comes from the log source of type
Physical Access. The other event comes from the Custom Rule Engine. The Username that is
involved in this offense is Eric Williams.
6. Click Reference Data Management and refresh the Employee_badge_expired Reference Set.