C1000-163 · Question #63
To review the internal changes done in Qradar, what log source in log activity tab must be selected?
The correct answer is A. SIM Audit. SIM Audit is the correct log source because QRadar uses it to record all internal system activities - including configuration changes, rule modifications, user actions, and administrative operations performed within the SIEM itself. It is specifically designed to provide an…
Question
To review the internal changes done in Qradar, what log source in log activity tab must be selected?
Options
- ASIM Audit
- BAsset profile
- CSystem notification
- DSIM Generic events
How the community answered
(58 responses)- A74% (43)
- B3% (2)
- C14% (8)
- D9% (5)
Explanation
SIM Audit is the correct log source because QRadar uses it to record all internal system activities - including configuration changes, rule modifications, user actions, and administrative operations performed within the SIEM itself. It is specifically designed to provide an audit trail of what changed inside QRadar.
Why the distractors are wrong:
- B. Asset Profile tracks discovered network assets and their properties, not internal system changes.
- C. System Notification surfaces health alerts and operational warnings (e.g., disk usage, license issues), not configuration audit events.
- D. SIM Generic Events is a catch-all category for events that don't map to a specific log source - it is not an audit mechanism.
Memory tip: Think of SIM Audit as QRadar's own diary - whenever an admin makes a change inside QRadar, SIM Audit writes it down. "Audit" = internal accountability log.
Topics
Community Discussion
No community discussion yet for this question.