Digital Developer Conference: a FREE half-day online conference focused on AI & Cloud – North America: Nov 2 – India: Nov 9 – Europe: Nov 14 – Asia Nov 23 Register now

Close outline
  • United States
IBM?
  • Site map
IBM?
  • Marketplace

  • Close
    Search
  • Sign in
    • Sign in
    • Register
  • IBM Navigation
IBM Developer Answers
  • Spaces
    • Blockchain
    • IBM Cloud platform
    • Internet of Things
    • Predictive Analytics
    • Watson
    • See all spaces
  • Tags
  • Users
  • Badges
  • FAQ
  • Help
Close

Name

Community

  • Learn
  • Develop
  • Connect

Discover IBM

  • ConnectMarketplace
  • Products
  • Services
  • Industries
  • Careers
  • Partners
  • Support
10.190.13.195

Refine your search by using the following advanced search options.

Criteria Usage
Questions with keyword1 or keyword2 keyword1 keyword2
Questions with a mandatory word, e.g. keyword2 keyword1 +keyword2
Questions excluding a word, e.g. keyword2 keyword1 -keyword2
Questions with keyword(s) and a specific tag keyword1 [tag1]
Questions with keyword(s) and either of two or more specific tags keyword1 [tag1] [tag2]
To search for all posts by a user or all posts with a specific tag, start typing and choose from the suggestion list. Do not use a plus or minus sign with a tag, e.g., +[tag1].
  • Ask a question

How to create a rule that will capture if a search is running longer than 9 minutes?

310000Q78U gravatar image
Question by ahmar74  (26) | Jan 26, 2017 at 11:29 AM qradartechnoteswg21984857

if someone is running a search query that is taking much time i want an alert created.

People who like this

  0
Comment
10 |3000 characters needed characters left characters exceeded
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster

3 answers

  • Sort: 
270006EH0R gravatar image
Accepted answer

Answer by JonathanPechtaIBM (8228) | Jan 26, 2017 at 01:35 PM

@ahmar74,

Your best bet is to not use a rule, but instead in QRadar 7.2.8 we introduced a feature called "Resource Restriction". I believe that this created an audit event, which could then be keyed off of, but I will have to run a quick test to verify that happen when a restriction is put in to effect.

Resource restriction allows you to specify users, roles, or tenants and then apply a resource restriction against individuals, groups, or tenants to ensure things like new users don't run 6 month searches that take days to run.

You have the option to define the following:
1. Records - Events/Flows query would be automatically stopped after the it reaches the assigned number of records.
2. Time range - Events/Flows query would be limited to the assigned time range. i.e. 3 days would allow a search to run 3 days backwards from the current time.
3. Execution time - Events/Flows query would be automatically stopped after the assigned period of time.

You are probably better off just assigning an execution time to that user, then you don't have to worry about a rule; however, if you wanted a metric to track there might be an audit event generated..I would have to test this as mentioned above.

Resource Restriction in QRadar 7.2.8


resource.png (45.8 kB)
Comment

People who like this

  0   Show 1   Share
10 |3000 characters needed characters left characters exceeded
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster
310000Q78U gravatar image ahmar74 (26)   Jan 26, 2017 at 01:38 PM 0
Share

currently we are running 7.2.7 patch 4, some of our users may run long searches bogging down the system, i want to be alerted when that happens but i am not the correct way to go about it. Thanks.

31000079RG gravatar image

Answer by Mike Hardesty (342) | Jan 26, 2017 at 01:22 PM

Might not be the answer you are looking for but why not set Resource Restrictions for execution time?

Comment
JonathanPechtaIBM

People who like this

  1   Share
10 |3000 characters needed characters left characters exceeded
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster
502SAUTS6G gravatar image

Answer by VishnuKarthick (1) | Jan 27, 2017 at 04:20 AM

@ahmar74,

I agree with Jonathan on using the “Resource Restriction” in 7.2.8. Having said that if you aren’t intending to upgrade soon, you can achieve expensive search notification by monitoring the "/store/transient/ariel.ariel_proxy_server/data" directory. This directory holds the search related information and the search results as well. We can start by identifying the search results(*.data) file with huge size, for example we can set the benchmark size as 5 GB.

In 7.2.6, To create an automated solution, we developed a script which will monitor this folder for say every 5 mins to see if any data file size is more than 5 GB, if any file is found with size bigger than 5 GB, the script can get into the alias file(Contains the user details of who initiated the search) associated with the data file to identify the user details and can notify. I’m not sure how the structure is in 7.2.7, you may want to check the same. Incase you need further details, you can PM me.

Examples of data and alias files

  • Data file: "4d479eb2-511a-4d5e-81a9-33002391adb4.data"

  • Alias File: "4d479eb2-511a-4d5e-81a9-33002391adb4~4d479eb2-511a-4d5e-81a9-33002391adb4.alias"

Comment

People who like this

  0   Share
10 |3000 characters needed characters left characters exceeded
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster

Follow this question

103 people are following this question.

Answers

Answers & comments

Related questions

Announcement: QVM Externally Hosted Scans (March 1st - power outtage) 0 Answers

Reporting on policy questions 2 Answers

Search results are not shown in log activity tab 0 Answers

How to capture an amount greater than 24001 but not more than 27000 via regex 3 Answers

is this a right statement? 1 Answer

  • Contact
  • Privacy
  • IBM Developer Terms of use
  • Accessibility
  • Report Abuse
  • Cookie Preferences

Powered by AnswerHub

Authentication check. Please ignore.
  • Anonymous
  • Sign in
  • Create
  • Ask a question
  • Spaces
  • API Connect
  • Analytic Hybrid Cloud Core
  • Application Performance Management
  • Appsecdev
  • BPM
  • Blockchain
  • Business Transaction Intelligence
  • CAPI
  • CAPI SNAP
  • CICS
  • Cloud Analytics
  • Cloud Automation
  • Cloud Object Storage
  • Cloud marketplace
  • Collaboration
  • Content Services (ECM)
  • Continuous Testing
  • Courses
  • Customer Experience Analytics
  • DB2 LUW
  • Data and AI
  • DataPower
  • Decision Optimization
  • DevOps Build
  • DevOps Services
  • Developers IBM MX
  • Digital Commerce
  • Digital Experience
  • Finance
  • Global Entrepreneur Program
  • Hadoop
  • Hybrid Cloud Core
  • Hyper Protect
  • IBM Cloud platform
  • IBM Design
  • IBM Forms Experience Builder
  • IBM Maximo Developer
  • IBM StoredIQ
  • IBM StoredIQ-Cartridges
  • IIDR
  • ITOA
  • InformationServer
  • Integration Bus
  • Internet of Things
  • Kenexa
  • Linux on Power
  • LinuxONE
  • MDM
  • Mainframe
  • Messaging
  • Node.js
  • ODM
  • Open
  • PartnerWorld Developer Support
  • PowerAI
  • PowerVC
  • Predictive Analytics
  • Product Insights
  • PureData for Analytics
  • Push
  • QRadar App Development
  • Run Book Automation
  • Search Insights
  • Security Core
  • Storage
  • Storage Core
  • Streamsdev
  • Supply Chain Business Network
  • Supply Chain Insights
  • Swift
  • UBX Capture
  • Universal Behavior Exchange
  • UrbanCode
  • WASdev
  • WSRR
  • Watson
  • Watson Campaign Automation
  • Watson Content Hub
  • Watson Marketing Insights
  • dW Answers Help
  • dW Premium
  • developerWorks Sandbox
  • developerWorks Team
  • Watson Health
  • More
  • Tags
  • Questions
  • Users
  • Badges