C1000-026 · Question #22
Which event routing rule is required to add QRadar Data Store (QDS) capability to a deployment?
The correct answer is A. Log Only (exclude Analytics). Log Only (exclude Analytics) is correct because QRadar Data Store is specifically designed as a high-volume, cost-efficient raw log repository that bypasses the analytics/correlation pipeline. Applying the "Log Only" routing rule is the required mechanism to direct events into…
Question
Which event routing rule is required to add QRadar Data Store (QDS) capability to a deployment?
Options
- ALog Only (exclude Analytics)
- BDelete data When storage space is required
- CBypass Correlation
- DDelete data immediately after the retention period has expired
How the community answered
(65 responses)- A85% (55)
- B2% (1)
- C9% (6)
- D5% (3)
Explanation
Log Only (exclude Analytics) is correct because QRadar Data Store is specifically designed as a high-volume, cost-efficient raw log repository that bypasses the analytics/correlation pipeline. Applying the "Log Only" routing rule is the required mechanism to direct events into QDS, since QDS stores data without running it through the full event processing engine - exactly matching what "exclude Analytics" describes.
Why the distractors are wrong:
- B (Delete when storage is required) is a data retention/eviction policy, not a routing rule that enables a storage tier.
- C (Bypass Correlation) skips correlation but still sends events through other analytics processing; it doesn't activate the QDS storage path.
- D (Delete immediately after retention period) is another data lifecycle/cleanup policy, unrelated to adding a new storage capability.
Memory tip: Think of QDS as a "cold warehouse" - you ship raw goods there to store cheaply, not to process them. Log Only = store only, no analytics - the name itself tells you what QDS does. If you remember that QDS = logging without analysis, option A becomes the only logical match.
Topics
Community Discussion
No community discussion yet for this question.