filmov
tv
QRadar: AQL Tutorial Part 1. Documentation and basic syntax.
Показать описание
Special Thanks to Mutaz Alsallal (IBM Poland) for the material shown here.
Here are some of the AQL commands so you can copy/paste:
select * from events START '2016-06-07 10:29:00' STOP '2016-06-07 13:53:00'
SELECT * FROM events WHERE magnitude BETWEEN 1 AND 5
SELECT * FROM events WHERE sourceip = '192.168.60.56' and destinationip != '64.4.44.76' START '2016-06-07 10:29:00' STOP '2016-06-07 13:53:00'
select * from events where not INCIDR('9.128.28.0/24',sourceip)
SELECT qidname(qid), * FROM events WHERE qidname(qid) ILIKE '%logon%' START '2016-06-07 10:29:00' STOP '2016-06-07 13:53:00'
Here are some of the AQL commands so you can copy/paste:
select * from events START '2016-06-07 10:29:00' STOP '2016-06-07 13:53:00'
SELECT * FROM events WHERE magnitude BETWEEN 1 AND 5
SELECT * FROM events WHERE sourceip = '192.168.60.56' and destinationip != '64.4.44.76' START '2016-06-07 10:29:00' STOP '2016-06-07 13:53:00'
select * from events where not INCIDR('9.128.28.0/24',sourceip)
SELECT qidname(qid), * FROM events WHERE qidname(qid) ILIKE '%logon%' START '2016-06-07 10:29:00' STOP '2016-06-07 13:53:00'
QRadar: AQL Tutorial Part 1. Documentation and basic syntax.
QRadar: Performing AQL searches Part 1
IBM QRadar AQL for IR - Part 1
QRadar Application Example with AQL via REST API Part 1
QRadar Flow Tutorial. Part One
QRadar: AQL Tutorial Part 2. Very useful AQL functions:
QRadar DSM Tutorial Part One
QRadar Tutorial Part 1 Offenses 1025, 885 and 953
Show QRadar in 30 minutes, no power no point, Part 1
QRadar Detecting Sophisticated Attacks on Windows Part One
Simple Tricks To Improve your QRadar Part One
Advanced Searches in QRadar. Part 1: Introduction
Mapping Flows to Applications in QRadar, Part 1
QRadar basics and Big Data
QRadar AQL Tutorial Part 4. Investigating APTs using AQL
QRadar AQL Tutorial Part 3. Leveraging the X-Force calls:
Searching in QRadar Part One: Ariel Searches
Qradar AQL Tutorial Part 6 Custom Functions
QRadar: Mainframe logs in real time Part One
Section 14 - Working with the API - Lecture 1: QRadar API Basics
QRadar UBA version 1 2
QRadar Searches in Six Minutes
QRadar AQL Tutorial Part 5. Nested IF/ELSE and CASE statements
Tutorial: QRadar CE SIEM - Installation and Configuration (Complete Steps)
Комментарии