Skip to main content
User guide

Security posture

The first screen after login: offenses in the window, high-severity count, log sources at risk, platform issues, and the top-10 noisiest rules and newest offenses.

Security posture generates nothing; it gathers the figures from Offenses, the log-source catalogue, Platform health and Investigations, refreshing every 30 s (pausable). In every edition.

Key figures

CardSourceClick goes to
AlertsOffenses synced within the windowOffenses
Critical + highSame, critical and high only; flagged "Look first" when non-zeroOffenses (severity filter applied)
Log sources at riskCatalogue entries in Error / Disconnected, or silent for 6 h (RST_PLATFORM_STALE_WARN_H); "QRadar not connected" before the first connectionPlatform health
Platform issuesChecks not passing in the latest runPlatform health

The window is the picker top-right, 24 hours by default.

Timeline and severity mix

Stacked counts per severity per hour (per day for wide windows), with the severity share of the window beside it. Severity derives from magnitude.

Noisiest rules / newest offenses

  • Noisiest rules, top 10: "View" opens Offenses filtered to that rule. One noisy rule often owns most of the queue; start here. Changing the rule happens in QRadar; Rule copilot can suggest the tuning.
  • Newest offenses, top 10: severity / rule / subject / time, with a search box; "Handle" opens the feed.

Archive

The bottom line shows how many investigations and triage runs are archived, linking to Investigations.

The small cards above the Ask AI home (open offenses, log sources at risk, platform issues, investigations) are a condensed version of this page.

On this page