Cyber Monday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IBM Exam C1000-156 Topic 4 Question 7 Discussion

Actual exam question for IBM's C1000-156 exam
Question #: 7
Topic #: 4
[All C1000-156 Questions]

What are some of the supported custom property expression types in QRadar?

Show Suggested Answer Hide Answer
Suggested Answer: B

IBM QRadar SIEM supports various types of custom property expressions to allow users to extract and parse data from logs in flexible and powerful ways. Among the supported custom property expression types, Regex, JSON, and LEEF are frequently utilized:

Regex (Regular Expressions): Regular expressions are a powerful tool used for pattern matching and extraction in text. In QRadar, regex can be used to create custom properties that parse specific patterns from log data, allowing for detailed and precise data extraction.

JSON (JavaScript Object Notation): JSON is a widely used data interchange format that is lightweight and easy to read and write. QRadar supports JSON expressions to parse and extract structured data from logs formatted in JSON.

LEEF (Log Event Extended Format): LEEF is a log format used by various devices to structure log data in a consistent manner. QRadar can utilize LEEF expressions to extract data from logs that use this format.

These types of expressions enhance QRadar's ability to handle diverse log formats and enable more accurate and efficient data analysis.

Reference IBM Security QRadar SIEM and IBM Security QRadar EDR integration.pdf


Contribute your Thoughts:

Lewis
5 months ago
I feel like I'm back in my database management class. RDBMS should definitely be an option here. I'm going with B, but with a bit of hesitation.
upvoted 0 times
Roslyn
4 months ago
I think Regex is crucial too. I'll choose D.
upvoted 0 times
...
Carlton
5 months ago
I agree, RDBMS is important. I'm going with A.
upvoted 0 times
...
...
Sheridan
5 months ago
Regex, JSON, and LEEF - that's the holy trinity of QRadar custom properties. B is the way to go, no doubt.
upvoted 0 times
...
Annamaria
5 months ago
Haha, HTML as a custom property expression type? What is this, a web design exam? Definitely going with B.
upvoted 0 times
Nan
4 months ago
B) Regex, JSON, LEEF
upvoted 0 times
...
Justine
4 months ago
Yeah, HTML does seem odd. B it is.
upvoted 0 times
...
Dwight
4 months ago
I agree, HTML seems out of place here. B does seem like the most logical choice.
upvoted 0 times
...
Ming
5 months ago
B) Regex, JSON, LEEF
upvoted 0 times
...
...
Whitney
5 months ago
I think the correct answer is D) Regex, JSON, HTML because those are commonly used in QRadar.
upvoted 0 times
...
Rodrigo
5 months ago
But I read somewhere that RDBMS is also supported.
upvoted 0 times
...
Avery
6 months ago
I'm a little iffy on the options here. Shouldn't RDBMS be one of the choices? I thought that was a core part of QRadar's capabilities.
upvoted 0 times
Benedict
5 months ago
I think the correct options are Regex, RDBMS, LEEF for supported custom property expression types in QRadar.
upvoted 0 times
...
Benedict
5 months ago
Yes, RDBMS is actually supported in QRadar for custom property expression types.
upvoted 0 times
...
...
Teri
6 months ago
I believe it's Regex, JSON, LEEF.
upvoted 0 times
...
Rodrigo
6 months ago
I think the supported custom property expression types in QRadar are Regex, RDBMS, LEEF.
upvoted 0 times
...
Berry
6 months ago
Option B seems the most accurate to me. Regex, JSON, and LEEF are definitely supported in QRadar.
upvoted 0 times
Chanel
5 months ago
I'm leaning towards option A. Regex and LEEF are supported, but I'm not sure about RDBMS.
upvoted 0 times
...
Refugia
5 months ago
I think option D might be a possibility too. Regex and JSON are definitely supported, but I'm not sure about HTML.
upvoted 0 times
...
Danica
5 months ago
I agree, option B is the correct one. Regex, JSON, and LEEF are indeed supported in QRadar.
upvoted 0 times
...
...

Save Cancel