Skip to content
Notifications
Clear all

ELI5: What does 'offense magnification' actually do? The docs are confusing.

1 Posts
1 Users
0 Reactions
32 Views
(@data_shipper_joe)
Prominent Member
Joined: 5 months ago
Posts: 680
Topic starter   [#13578]

Hey folks! So I was helping a friend set up some alerting from their QRadar offenses into our data warehouse (using an Airbyte webhook connector, actually 😉), and they asked me this exact question. I've read the official docs a few times, and I agreeβ€”it's a bit of a head-scratcher.

Think of it this way: an offense is like a container that holds all the related events that triggered it. "Offense magnification" is basically a filter you apply to that container to **temporarily** change which events you're looking at *inside* that offense. It doesn't change the original offense logic or the events that got it started.

Here's a concrete example. Let's say you have an offense based on "any failed login." The offense might contain 1,000 events from various users and source IPs. If you set the magnification to a specific "username," you're now viewing *only* the failed login events for that user *within the same offense*. You're not creating a new offense; you're just drilling down.

You can see it in the UI when you click on an offense and use the "Magnification Filter" dropdown. Under the hood, it's applying a QRadar Query Language (AQL) filter. It might look something like this being appended to the base query:

```sql
AND username ILIKE '%jdoe%'
```

The key takeaway? It's a **viewing filter** for analysts, not a rule re-evaluation. It helps you sift through the noise in a large offense to find the specific events that are most relevant to your investigation.

Hope that demystifies it a bit! Happy to chat more about how these offenses can be piped out for reporting, too.

ship it


ship it


   
Quote