A QRadar facelift.
6:48
Ай бұрын
Searches against User Data
6:03
3 ай бұрын
Free QRadar CE, installation video
11:42
QRadar Status Report
4:30
4 ай бұрын
Parsing Primer
16:10
5 ай бұрын
Where do I need Regex in QRadar
7:31
Anything but. Regex
3:14
6 ай бұрын
Non greedy Regex
3:33
6 ай бұрын
Regex for a URL and subdomains
4:41
Regex for  an IP V4 address
4:16
6 ай бұрын
NexGen SIEM Part One
14:00
6 ай бұрын
EPS License Give Back
1:41
6 ай бұрын
EPS consumption per log source
4:06
Even More Cool UCM Reports
3:05
7 ай бұрын
Automatic XForce Lookups
2:50
8 ай бұрын
Interview with Nigel Sood
9:30
Жыл бұрын
Sigma to QRadar Rule Converter
9:47
Пікірлер
@lakshmanchinthala3864
@lakshmanchinthala3864 21 сағат бұрын
Very clear and Straight forward explanation and it is crystal clear!
@ihacksi
@ihacksi Күн бұрын
Thanks for sharing your insights, we need more of this!
@KevinBrown-f1d
@KevinBrown-f1d 12 күн бұрын
Schuster Meadow
@CharlesHarris-r6d
@CharlesHarris-r6d 13 күн бұрын
Wilson Larry Robinson Edward Robinson Sandra
@ArthiMohan-c6d
@ArthiMohan-c6d 22 күн бұрын
God bless you Jose....save this video!❤
@yamircontreras9229
@yamircontreras9229 23 күн бұрын
Don José Bravo usted es increíble.. lo que andaba buscando
@FaviolaBush
@FaviolaBush 23 күн бұрын
9572 Metz Villages
@ishworshrestha5699
@ishworshrestha5699 23 күн бұрын
Hi Jose, Can you please make a video for joining two devices in log activity and displaying two devices' custom property in a single row?
@sportyoff
@sportyoff 26 күн бұрын
pls make video about installing QRadar CE 7.5 on VMware or VirtualBox
@vinyldown8490
@vinyldown8490 29 күн бұрын
It is still the ugliest product out there :P , yes it does its job but its the one i hate the most.
@JosueLawyer-o7n
@JosueLawyer-o7n 29 күн бұрын
Powlowski Crossing
@yonimihaelov8785
@yonimihaelov8785 Ай бұрын
Idk i try to ping with my defualt gateway and host unrtable but its the same subnet . I confuse
@yonimihaelov8785
@yonimihaelov8785 Ай бұрын
ok now i have ping but i cant go to website
@sportyoff
@sportyoff 26 күн бұрын
@@yonimihaelov8785 are you fix it?
@RubenMuñozAragon-e9n
@RubenMuñozAragon-e9n Ай бұрын
Gracias compañero. Estoy estudiando Splunk y QRadar.
@alireza8923
@alireza8923 Ай бұрын
Whats facelift?
@jbravovideos
@jbravovideos 28 күн бұрын
A minor plastic surgery use to stretch the skin in the face to get rid of wrinkles that come with aging
@MJEHANZEBJAFRI
@MJEHANZEBJAFRI Ай бұрын
Where we get the Secret Keys???
@sidss007
@sidss007 Ай бұрын
My 7.5 community edition installed properly. Everything seems to be working fine but the web page isn't opening. Tomcat service is working fine but still the web page doesn't opens.
@winrar9979
@winrar9979 Ай бұрын
Same issue with me, i followed each step double checked everything but still not result with the web page
@sidss007
@sidss007 Ай бұрын
@@winrar9979 my issue has been resolved. I made this lab in my office infra, so our proxy server was blocking my request. Hence web page wasn't opening.
@DoddEmmanuel-c7f
@DoddEmmanuel-c7f Ай бұрын
Tromp River
@rafaeldsdias
@rafaeldsdias Ай бұрын
Thank you, the video is very good, but towards the end, when creating the custom attribute in the AQL expression, the key 'EventID' returns an error stating it doesn't exist. The accepted value is 'Event ID' with a space between 'Event' and 'ID'.
@programacion3694
@programacion3694 Ай бұрын
interesante
@BooHeeee
@BooHeeee Ай бұрын
The goat
@Kumar-ez2bs
@Kumar-ez2bs Ай бұрын
QNI need flow processor?
@jbravovideos
@jbravovideos 28 күн бұрын
If done with HW the appliance use some specialized network cards. However recent version allows this to be done by SW. Typically you will use a flow processor, but it can reside in a AIO (all in one) box like in my lab.
@Kumar-ez2bs
@Kumar-ez2bs 28 күн бұрын
@@jbravovideos thanks🙏🏻
@jumpmanjxhnsxn7608
@jumpmanjxhnsxn7608 2 ай бұрын
bravo!
@FunCity260
@FunCity260 2 ай бұрын
Hey IBM this QRadar GUI is so old school, looks like Windows 95. Please work on your interface better now than late. I know your SIEM is so powerful.
@raheel7183
@raheel7183 2 ай бұрын
Really Helpful :)
@tritruong1590
@tritruong1590 2 ай бұрын
What is the Apple CPU chip you are using?
@jbravovideos
@jbravovideos 28 күн бұрын
An old Mac Pro late 2013
@lexbrown467
@lexbrown467 2 ай бұрын
Please how can i get my hostname
@jbravovideos
@jbravovideos 28 күн бұрын
open a command prompt and type hostname
@lizjorge9318
@lizjorge9318 2 ай бұрын
the BEST EXPLANATION of CIDR subnetting i've come across!! Thank you so much for this easy to understand breakdown, Jose.😀
@jbravovideos
@jbravovideos 28 күн бұрын
Glad it was helpful!
@MUZAMMILAHMED-vj6cd
@MUZAMMILAHMED-vj6cd 2 ай бұрын
i found very difficult to install 7.5 version
@ihacksi
@ihacksi Ай бұрын
mine also fails, creates a lot of issues. Qradar is a very delicate product!
@adityanjsg99
@adityanjsg99 2 ай бұрын
centuries of consfusion cleared!
@devendramhatre5090
@devendramhatre5090 2 ай бұрын
How to check Hash reputation or Hash Category like we are using for IP - XFORCE_IP_CATEGORY and XFORCE_IP_CONFIDENCE, wht should we use for Hash?
@srdjus4064
@srdjus4064 2 ай бұрын
For some reason, systemctl fails when starting tomcat service. Even though I did everything step by step. Regardless, thank you for this and other videos on channel, it is really helpful. EDIT: I fixed it. If you are using VirtualBox or KVM based solution, you should choose software install at 5:39.
@Yasiff
@Yasiff 14 күн бұрын
bro if iam vmware i would choose software instalion? because i started tomcat but it is failed
@osamaahmed4341
@osamaahmed4341 3 ай бұрын
could you pls provide the logs files used to test the use case .
@BrunoOlivera22
@BrunoOlivera22 3 ай бұрын
thx!!
@jeffer8762
@jeffer8762 4 ай бұрын
always looking forward to your video regarding qradar
@florenciadesantis2255
@florenciadesantis2255 4 ай бұрын
Hi, the security information area want to integrate SAP S4 Hana with qradar. Our SAP platform is on HEC cloud. I don’t understand where we have to install the SAP tread, Is it an add on of SAP? Or of qradar?
@alifkurnia155
@alifkurnia155 4 ай бұрын
Can I Get the PDF of your list video that you are showing in the video?
@jbravovideos
@jbravovideos 4 ай бұрын
I put this in the video description of all my videos: "Link to a Box folder with a file with an index of the most recent videos, go to the last page and look for a file named Security Intelligence Tutorial, Demos & Uses Cases Version XXX.pdf" ibm.ent.box.com/s/ich0yyiw54y0ek6s9a66xvtjku8e42rc
@thonau_712
@thonau_712 4 ай бұрын
Glad to see you released a new video.
@jbravovideos
@jbravovideos 4 ай бұрын
Me too!
@cyberlancer718
@cyberlancer718 4 ай бұрын
Great you are back again ❤️
@jbravovideos
@jbravovideos 4 ай бұрын
Thanks
@truetimor
@truetimor 4 ай бұрын
💡👌🏻
@jbravovideos
@jbravovideos 4 ай бұрын
Thanks
@sion7651
@sion7651 4 ай бұрын
good explanation. i am searching for the opposit. i want my Firewall only accessible from a certain IP. i dont want it to be publicly seen. i want ping on the WAN address to fail and the webconfigurater should not appear.
@marcoaureliodeoliveira399
@marcoaureliodeoliveira399 4 ай бұрын
Excellent class, it will help me a lot in my work journey, Thanks for sharing.
@sreenivasp4720
@sreenivasp4720 4 ай бұрын
Very well explained Sir
@TonFelix-h4i
@TonFelix-h4i 4 ай бұрын
Congratulations on the video, I would like to know where I can find the pfsense_custon_ext file? I looked in the folders and found some;
@thonau_712
@thonau_712 5 ай бұрын
Your videos and articles have helped me in using IBM QRadar SIEM. Since my organization provides monitoring, adding, and editing rule sets for anomaly detection, we do not provide IBM QRadar SIEM implementations because our customers purchased IBM QRadar SIEMs from before. I am the person responsible for adding and editing rule sets and my manager assigned me to build an anomaly detection rule set on IBM QRadar itself. Since our client doesn't allow us to add extensions ourselves, I have to deploy QRadar CE myself, I'm wanting to use an extension called: IBM QRadar Security Analytics Self Monitoring, which version of QRadar CE is 7.3.3, is not compatible with the version on App Exchange. If you have a previous version compatible with QRadar CE please share it with me. Thank you very much I just discovered that IBM has updated the CE version to 7.5 UP8, can install the latest extensions, problem solved. Once again, thank you for your free useful content..
@RobsonBadam
@RobsonBadam 5 ай бұрын
How are you, José? Could you help me include a SELECT sourceip attribute, GEO::LOOKUP(sourceip, 'city') in the same format as X-Force?
@jouiniahmed4349
@jouiniahmed4349 5 ай бұрын
Could you please prepare video how using Jupiter playbook with qradar/kestrel threat hunting.thank you in advance
@Subhan_Ahmad
@Subhan_Ahmad 5 ай бұрын
Hi, I follow all your content and its really helpful for me. Please make a video on QRadar Upgradation for Distributed environment.
@yarinlevy16
@yarinlevy16 5 ай бұрын
Hi Jose, Hi, I saw that the connection of cloudflare using http receiver is now different in qradar It is necessary to load certificates Can you make a video where you show exactly which certificate needs to be loaded and how you connect the log source Thanks in advance
@grettelriverarojas4547
@grettelriverarojas4547 Ай бұрын
Please , as soon you have it , upload it
@NeoYOYO173
@NeoYOYO173 5 ай бұрын
How the heck to to break into 2 subnets . What is the math behind that?
@IbraheemKhazbak
@IbraheemKhazbak 5 ай бұрын
using more routers where each router gets a part of the network
@muhammadqavikaleemkhan252
@muhammadqavikaleemkhan252 5 ай бұрын
This shared file or folder link has been removed or is unavailable to you.