- play_arrow QRadar Use Case Manager
- play_arrow What's New in QRadar Use Case Manager
- play_arrow Known Issues
- play_arrow Video Demonstrations
- play_arrow Supported Environments for QRadar Use Case Manager
- play_arrow Installation and Configuration Checklist
- Installation and Configuration Checklist
- Installing QRadar Use Case Manager
- Creating an Authorized Service Token
- Configuring the Use Case Explorer in QRadar Use Case Manager
- Assigning User Permissions for QRadar Use Case Manager
- Customizing User Preferences
- Predefined Report Content Templates
- Customizing Report Content Templates
- Custom Rule Attributes
- Creating Custom Rule Attributes
- Exporting and Importing Custom Rule Attributes
- Upgrading QRadar Use Case Manager
- Uninstalling QRadar Use Case Manager
- play_arrow MITRE ATT&CK Mapping and Visualization
- MITRE ATT&CK Mapping and Visualization
- Editing MITRE Mappings in a Rule or Building Block
- Editing MITRE Mappings in Multiple Rules or Building Blocks
- Sharing MITRE-mapping Files
- Visualizing MITRE Tactic and Technique Coverage in Your Environment
- Visualizing MITRE Coverage Summary and Trends
- Visualizing MITRE Tactics and Techniques that are Detected in a Specific Timeframe
- MITRE Heat Map Calculations
- play_arrow Investigating QRadar Rules and Building Blocks
- Investigating QRadar Rules and Building Blocks
- Filtering Rules and Building Blocks by their Properties
- Identifying Gaps in QRadar Rule Coverage from Content Extensions
- Investigating User Behavior Analytics Rules
- Duplicating Rules for Further Customization
- Exporting Rules
- Deleting Rules
- Rule Report Presentation
- Visualizing Rules and Building Blocks
- Visualizing Log Source Type Coverage per Rule
- play_arrow Accessing Report Data by using QRadar Use Case Manager APIs
Reviewing Building Blocks
Building blocks are a reusable set of rule tests that can be used within rules when needed. Host definition building blocks (BB:HostDefinition) categorize assets and server types into CIDR/IP ranges. By populating host definition building blocks, QRadar can identify the type of appliance that belongs to an address or address range. These building blocks can then be used in rules to exclude or include entire asset categories in rule tests.
Use server discovery to populate host definition building blocks (BB:HostDefinition). Server discovery uses existing asset profile data so that administrators can define unknown server types and then assign them to a server definition and the network hierarchy.