1. IBM QRadar SIEM User Guide (Version 7.5.0), Chapter 6: "Investigating events", Section: "Event investigation columns", Page 62. This section details the columns available in the Log Activity tab, noting that the default display includes columns "commonly used for event investigations," such as Log Source, Event Count, and category information. The presence of an offense indicator is also a standard UI element.
2. IBM Security Learning Academy, Course BQ103G: IBM QRadar SIEM Foundations, Unit 5: "Investigating an Offense Triggered by Events". The lab exercises and user interface demonstrations in this official course consistently show Log Source, Event Count, and Category information as primary columns in the default Log Activity view. The link between events and offenses is a core concept, making the Related Offense information a key default element.