What type of custom property should be used when an analyst wants to combine extraction-based URLs, virus names, and secondary user names into a single property?
- AOL-based property
- Absolution-based property
- Extraction-based property
- Calculation-based property
Answer(s): A
Explanation:
When an analyst wants to combine multiple extraction and calculation-based properties into a single property, such as URLs, virus names, and secondary user names, an AQL-based property should be used. AQL (Ariel Query Language)-based properties allow for the aggregation of diverse data types into a unified custom property, facilitating more flexible and comprehensive data analysis within QRadar.
Reveal Solution Next Question