Security posture
The first screen after login: offenses in the window, high-severity count, log sources at risk, platform issues, and the top-10 noisiest rules and newest offenses.
Security posture generates nothing; it gathers the figures from Offenses, the log-source catalogue, Platform health and Investigations, refreshing every 30 s (pausable). In every edition.
Key figures
| Card | Source | Click goes to |
|---|---|---|
| Alerts | Offenses synced within the window | Offenses |
| Critical + high | Same, critical and high only; flagged "Look first" when non-zero | Offenses (severity filter applied) |
| Log sources at risk | Catalogue entries in Error / Disconnected, or silent for 6 h (RST_PLATFORM_STALE_WARN_H); "QRadar not connected" before the first connection | Platform health |
| Platform issues | Checks not passing in the latest run | Platform health |
The window is the picker top-right, 24 hours by default.
Timeline and severity mix
Stacked counts per severity per hour (per day for wide windows), with the severity share of the window beside it. Severity derives from magnitude.
Noisiest rules / newest offenses
- Noisiest rules, top 10: "View" opens Offenses filtered to that rule. One noisy rule often owns most of the queue; start here. Changing the rule happens in QRadar; Rule copilot can suggest the tuning.
- Newest offenses, top 10: severity / rule / subject / time, with a search box; "Handle" opens the feed.
Archive
The bottom line shows how many investigations and triage runs are archived, linking to Investigations.
The small cards above the Ask AI home (open offenses, log sources at risk, platform issues, investigations) are a condensed version of this page.
Rule copilot
Describe the behaviour to catch in one sentence and get a QRadar Rule Wizard design: test conditions, rule response, backtest AQL, MITRE ATT&CK, checked against live rules for duplicates. Analysts configure the rule in the wizard; the product never writes to QRadar. Paid capability.
Reports
Daily / weekly / monthly: offense posture, top rules and entities, analysis activity, log-source health, model usage and health. Scheduled generation, archive and push.