IBM Support

QRadar: Why is the Save Results option disabled when creating or editing a search in the Log Activity tab?

Question & Answer


Question

When users create a new search or edit an existing search (Log Activity > Search > New Search OR Log Activity > Search > Edit Search), there is an option to save the results when the search finishes. In some instances, the Save Results option is disabled. How to enable the Save Results option?
image 6508

Cause

When users create or edit searches, there is a Time Range option that can be set to one of the following values:
image 6509
As the names suggest, the Real Time (streaming) and Last Interval (auto refresh) options lead to dynamic search results that cannot be saved. On the other hand, the Recent or Specific Interval options lead to static search results that can be saved.

Answer

Choose the Recent or Specific Interval options under Time Range:
image 6519
image 6517
Result:
The Save Results option is then enabled and the search results can be saved.
image 6510

[{"Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000cwtEAAQ","label":"Log Activity"}],"ARM Case Number":"TS004216359","Platform":[{"code":"PF016","label":"Linux"}],"Version":"All Version(s)"}]

Document Information

Modified date:
13 October 2020

UID

ibm16343225