filmov
tv
QRadar: AQL Tutorial Part 1. Documentation and basic syntax.
data:image/s3,"s3://crabby-images/984f5/984f5b75b53588ee7c861197385d2cc871244860" alt="preview_player"
Показать описание
Special Thanks to Mutaz Alsallal (IBM Poland) for the material shown here.
Here are some of the AQL commands so you can copy/paste:
select * from events START '2016-06-07 10:29:00' STOP '2016-06-07 13:53:00'
SELECT * FROM events WHERE magnitude BETWEEN 1 AND 5
SELECT * FROM events WHERE sourceip = '192.168.60.56' and destinationip != '64.4.44.76' START '2016-06-07 10:29:00' STOP '2016-06-07 13:53:00'
select * from events where not INCIDR('9.128.28.0/24',sourceip)
SELECT qidname(qid), * FROM events WHERE qidname(qid) ILIKE '%logon%' START '2016-06-07 10:29:00' STOP '2016-06-07 13:53:00'
Here are some of the AQL commands so you can copy/paste:
select * from events START '2016-06-07 10:29:00' STOP '2016-06-07 13:53:00'
SELECT * FROM events WHERE magnitude BETWEEN 1 AND 5
SELECT * FROM events WHERE sourceip = '192.168.60.56' and destinationip != '64.4.44.76' START '2016-06-07 10:29:00' STOP '2016-06-07 13:53:00'
select * from events where not INCIDR('9.128.28.0/24',sourceip)
SELECT qidname(qid), * FROM events WHERE qidname(qid) ILIKE '%logon%' START '2016-06-07 10:29:00' STOP '2016-06-07 13:53:00'
QRadar: AQL Tutorial Part 1. Documentation and basic syntax.
QRadar: Performing AQL searches Part 1
IBM QRadar AQL for IR - Part 1
QRadar Application Example with AQL via REST API Part 1
QRadar Flow Tutorial. Part One
QRadar: AQL Tutorial Part 2. Very useful AQL functions:
QRadar DSM Tutorial Part One
QRadar Tutorial Part 1 Offenses 1025, 885 and 953
Show QRadar in 30 minutes, no power no point, Part 1
QRadar Detecting Sophisticated Attacks on Windows Part One
Simple Tricks To Improve your QRadar Part One
Advanced Searches in QRadar. Part 1: Introduction
Mapping Flows to Applications in QRadar, Part 1
QRadar basics and Big Data
QRadar AQL Tutorial Part 4. Investigating APTs using AQL
QRadar AQL Tutorial Part 3. Leveraging the X-Force calls:
Searching in QRadar Part One: Ariel Searches
Qradar AQL Tutorial Part 6 Custom Functions
QRadar: Mainframe logs in real time Part One
Section 14 - Working with the API - Lecture 1: QRadar API Basics
QRadar UBA version 1 2
QRadar Searches in Six Minutes
QRadar AQL Tutorial Part 5. Nested IF/ELSE and CASE statements
Tutorial: QRadar CE SIEM - Installation and Configuration (Complete Steps)
Комментарии