Skip to main content
User guide

A tour of the UI

The two navigation groups, accounts and roles, the Ctrl+K command palette, and the quota bar while unactivated.

Login

https://<hostname>/v2/. The first account is the admin set by deploy.sh; there is no self-registration, people are added on the Users page.

Pages

The sidebar has two groups. Security posture, Settings and Platform health each carry in-page tabs holding the other seven pages.

GroupPageWhat
Security operationsSecurity postureOffense totals, high-severity count, log-source anomalies, platform issues; tabs for Offenses and Reports
Ask AIOne question over events / flows, follow-up turns
InvestigationsArchive of investigations, triage runs and result readings
TriageCluster, score and rank a batch of offenses (paid)
Rule copilotRule Wizard designs from one sentence (paid)
AdministrationPlatform healthQRadar deployment checks + AI reading (reading is paid); tabs for Audit log and Outbound channels
SettingsQRadar connection, log-source whitelist, masking, offense sync, online update; tabs for Users, AI settings, License

Command palette

Ctrl+K (⌘K on macOS) or the search box top-left: type a page name to jump, or browse recent query history.

Accounts and roles

The avatar top-right: current account and role, profile, preferences (language, light / dark theme), sign out. Language and theme are saved with the account and follow it across browsers.

RoleCan
AdminChange configuration, manage accounts, activate licences
AnalystQuery, investigate, triage, act on offenses (including notes / close / assign written back to QRadar); cannot change gateway configuration
ViewerQuery and read; changes nothing, including offenses

Quota while unactivated

Without an activated licence the free capabilities keep working under a daily LLM-call quota (200 by default, RST_TRIAL_DAILY_LIMIT). The bottom of the sidebar shows what is left today and when it resets. Activation removes the limit.

Two global notices

  • "Not connected to QRadar yet": no Console URL and token configured. Set them in Settings and test; until then queries, offenses and analysis have no data source. An expired token shows the same notice.
  • "Not synced": history / preferences / saved queries are only in this browser for now; they sync once the gateway is back.

On this page