A Deployment Professional has detected a big spike in a customer’s "Malware infection detected" rule that monitors their endpoint anti-virus solution. The spike happened over the weekend, but when the rule was checked, it was not changed. Since Monday morning, the rule has spiked and has not yet stopped generating offenses.What was added to the customer's QRadar log sources that caused this problem?
A customer has existing complex network infrastructure with many redundant links and the IP packets are taking different paths for inbound and outbound traffic. ADeployment Professional needs to configure SFlow.What should be configured in IBM Security QRadar SIEM V7.2.7 to support this specific case?
In IBM Security QRadar SIEM V7.2.7, the number of Aggregated Data Management Views were increased.How many additional views were added?
Two multi-site companies with international presences are merging and consolidating their operations. The companies have decided that the relevant information on each site must be available to the local users only.How should IBM Security QRadar SIEM V7.2.7 be configured to comply with this request?
A client has configured a log source to forward events to IBM Security QRadar SIEM V7.2.7. It is recommended that the log source level be configured at the notice level by the DSM Guide, but the client has a policy to log all events at a debug level.The Deployment Professional notices that the configured DSM is parsing most events, but some are being labeled as stored. The client is very interested in correlating some of the events that are being stored.What should be created to meet this client's goal?
A client has reached the maximum of 5000 EPS for their 3128 All-in-One appliance. They have just completed an acquisition of a competitor company and would like to get them on-board with collecting events for correlation in QRadar. It has been determined that the newly acquired company has a large number of log sources, and it is estimated that its total EPS will be approx. 22000 EPS.What will meet the hardware requirements when changing to a distributed environment?