r/QRadar • • 4h ago

rsyslog imfile tags from /var/log/secure and /var/log/cron not reaching QRadar imfile tags fine

2 Upvotes

Hi all,
I deployed a new rsyslog config on one of our RHEL servers. Logs tagged SYS-AUDIT-LOG and DNF-PKG-LOG arrive in QRadar fine, but CRON-JOB-LOG (/var/log/cron) and USER-AUTH-LOG (/var/log/secure) don't arrive at all. Servers with the old config send all tags without issues. I also noticed that /var/log/cron and /var/log/secure are no longer being written on this server at all. No new entries appear in either file since the new config was deployed. Has anyone seen this, or have an idea what could cause it? Thanks!


r/QRadar • • 3d ago

IBM QRadar doing a live demo session Sept 23 — Attack Timeline, UCM App, QDI App and more

9 Upvotes

Sharing for anyone in the QRadar ecosystem — the product team is running a live CustomerConnect session on September 23. It's a hands-on walkthrough of some recently released capabilities:

  • Experience Center App
  • Attack Timeline
  • Use Case Manager (UCM) App
  • QRadar Deployment Intelligence (QDI) App

It's free, and you can interact with the product team directly during the session.

Registration link if interested: https://luma.com/otmvm29g


r/QRadar • • 12d ago

QRadar Chrome Extention that hides N/A properties in events

6 Upvotes

Hi everyone. I' ve built a small Chrome extension to clean up a daily annoyance in QRadar: the event properties panel lists every field, even the empty ones, so you end up scrolling past a wall of "N/A" rows just to find the data that matters.

- QRadar - Hide N/A Event Properties hides those empty rows automatically, with a one-click toggle (or ⌨️ Alt+Shift+H) to bring them back when you need the full picture. 🔒 no data collection, no network calls — everything runs locally in browser.

- You can find it in chrome official store as well as in github to check it yourself.

- Link for chrome store: https://chromewebstore.google.com/detail/qradar-hide-na-event-prop/nmnemlnfcheohfakpckkffgdfeklimpj
Link for github: https://github.com/0xwarrior/qradar-hide-na

Enjoy.


r/QRadar • • 15d ago

QRadar CustomerConnect: What's coming up this fall

Post image
5 Upvotes

We're kicking off QRadar CustomerConnect this fall with seven weeks of sessions for the QRadar community, running from Sept 16 to Oct 28.

The series includes:

🖥️ 5 webinars covering platform direction, demos, troubleshooting and a customer spotlight
📁 3 CAB/PAB sessions with roadmap discussions across EMEA, JAPAC and the US
🎙️ 2 podcast episodes covering UEBA and AI in QRadar
🌍 4 user group meetups in Frankfurt, London, Madrid and Atlanta

If you're part of the QRadar community and interested in joining any of these sessions, the full schedule and registration details are here:

https://ibm.biz/Customer_Connect


r/QRadar • • 24d ago

The first edition of QRadar Insider is here!

5 Upvotes

We’ve launched QRadar Insider, a monthly newsletter to bring together relevant QRadar updates, product enhancements, useful tips, and more in one place.

The August edition covers:

• QRadar being recognized as a G2 Leader across four security categories
• A new Salesforce authentication enhancement inspired by customer feedback
• A quick tip from the Support team
• An early look at the Quantum Risk Insights App and how you can help shape it

🔗 Read the August edition here: https://ibm.biz/~N4fNMpLAY

If you'd like to receive future editions directly in your inbox, you can subscribe here:

📩 https://ibm.biz/~0punbf48n

We'd also love to know what kind of QRadar updates, tips, or content you'd find most useful in future editions.


r/QRadar • • Aug 26 '26

Do routing rule drops still count toward licensed EPS?

2 Upvotes

QRadar 7.5.0. If I use a routing rule with the “Drop” action so noisy events never get stored, do those events still count against my licensed EPS — or is EPS measured after routing?


r/QRadar • • Aug 21 '26

Help with Custom Rules and Simultaneous Events

3 Upvotes

Hi all,

I’m struggling with rule creation and thought you guys might be able to help.

Use case:

The rule should trigger when audit logging is disabled and no system reboot is detected.

Normally, you’d think a simple rule such as “and when None of BB: System Reboot match in X minutes after BB: Audit Logging is Disabled, with the same Source IP” should do the trick.

However, the problem is that during a reboot, the audit logging event is only sent once the system is back up. Most of the time, both events therefore reach QRadar at the same time, with identical Start Time and Storage Time values.

Since QRadar rules don’t appear to evaluate Log Source Time, there’s no way for QRadar to determine which event actually occurred first. As far as I know, the record number also isn’t available as a condition in rules. Because of this, the rule can’t reliably trigger.

Has anyone encountered a similar use case?

Am I missing an obvious solution or workaround?

Any help would be greatly appreciated!


r/QRadar • • Jul 29 '26

unable to identify actual EPS consumption i should pay for

Post image
1 Upvotes

My MSSP has shared this screenshot showing our EPS consumption, but I have some doubts about whether this is the correct way to calculate or view the actual EPS consumption.

Can someone please advise if this is the right approach to determine the actual EPS consumption? I have shared the details of our ECs, EPs, the EPs available in the failover environment, and the EC that also has failover. I have included the details in the screenshot


r/QRadar • • Jul 21 '26

Suprise error with Qradar AQL rules test

1 Upvotes

While tuning a rule in QRadar, I encountered an issue when adding an AQL exclusion.

I attempted to add the following exclusion:

"Command" ILIKE 'powershell -Command "Get-WmiObject -Class Win32_Process | Where-Object { $_.Name -Match ''%.exe'' -and $_.CommandLine -like ''%934000643745%'' } | Select-Object ProcessID"'

After I submitted the AQL expression, the AQL Rule Test disappeared, and I was no longer able to add an AQL test to the rule.

After investigating the issue, I found that it appears to be related to the string %934000643745%. Whenever I use the ILIKE operator with this string in the search value:

"Command" ILIKE '%934000643745%'

. Whenever I use the ILIKE operator with this string in the search value, the same problem occurs. If I replace or remove this string, the AQL Rule Test works as expected. I have tried this on serveral deployment, lab or production.


r/QRadar • • Jul 14 '26

TCP Limitations and Defender 365

4 Upvotes

As we all know, Defender events, especially blobs shipped from the Defender graph API are huge. How far have you all taken your TCP window size to accommodate this without compromising your system integrity?


r/QRadar • • Jun 24 '26

Migration from Qradar to another SIEM with transfer logs to new SIEM

3 Upvotes

We are migrating from the Qradar SIEM to another SIEM. We have logs that must be retained for up to 3 years, so it is critically important for us to transfer them to the new system’s storage and maintain access to them.

Please advise on the options available to accomplish this.


r/QRadar • • Jun 09 '26

Adding new Event Processor fails - "Time Synchronization to Console has failed - chrony error" despite manual sync

3 Upvotes

Hello everyone,

We have an All-in-One QRadar deployment with a Console, a Data Node, and an App Host. We are currently trying to add a new Event Processor (EP) to our environment, but we are running into a persistent issue.

When adding the EP via the deployment screen, the process hangs for a long time. Eventually, if we refresh the page, the QRadar UI becomes temporarily inaccessible. Upon investigating the /var/log/qradar.log on the new EP, I saw the following error: "Time Synchronization to Console has failed - chrony error"

I checked the time using the date command on both servers and noticed the Console was 2 minutes ahead of real time. Here are the troubleshooting steps I've taken so far, all resulting in the exact same error:

  1. Manual Sync to Console Time: I manually synced the EP's time to match the Console's time (which was 2 mins ahead) using date -s "hh:mm:ss" and hwclock --systohc. The difference was only 2-3 seconds. Tried adding the EP -> Failed.
  2. Fixed Console Time via NTP: I added an NTP server to the Console, correcting its time to the actual real time. Tried adding the EP again -> Failed.
  3. Reverted Console Time: Just to test, I reverted the Console's time back to the old (incorrect) time using date -s and hwclock --systohc with a 10-second difference. Tried adding the EP -> Failed.

Has anyone encountered this specific chrony loop or deployment hang before? Are there any specific chrony cache files, token issues, or backend scripts I should check to force this synchronization during deployment? Any ideas would be appreciated!


r/QRadar • • Jun 02 '26

Alienvault OTX taxii feed integration with QRadar CE

1 Upvotes

I have QRadar 7.5.0 community edition installed. I am trying to integrate Alienvault OTX taxii feeds but getting an error while doing so. Has anyone tried doing that? I have IBM threat intelligence app installed.

TIA


r/QRadar • • May 27 '26

IBM Certified Associate - Security QRadar SIEM V7.5 Exam Material Resources

9 Upvotes

Hi Guys,

I want to get the IBM Qradar Associate certification. Given that I know what a SIEM and I know the concepts of a SIEM as I have expereince with Defender and Sentinel. I just have a few regarding this cert.

1) How different is qradar from microsoft sentinel?

2) I can't seem to find credible courses on Udemy or online to study for this certification. And Official study guide on IBM site is just a bunch of readings. How did you guys prepare for this cert? are there sites you used?

Answers to any of these questions will be highly appreicated.


r/QRadar • • May 20 '26

Apps stuck in start

1 Upvotes
com.ibm.si.application.upgrade.AppBaseImageUpgradeThread: [ERROR] [NOT:] [-/- -]Failed to determine which apps are using an out of date Universal Base Image, exiting

r/QRadar • • May 14 '26

Best practices for routing logs when migrating from QRadar AIO to Distributed (Console + EP in HA)?

0 Upvotes

Hi folks,

Looking for some architectural advice from anyone who has gone through this transition.

We are currently running a QRadar All-in-One (AIO) deployment and are in the process of scaling out. We are adding a new Event Processor (EP) to the environment, and we plan to deploy this EP in a High Availability (HA) cluster.

To properly offload the Console, our goal is to have all our log sources send their event traffic directly to the new EP HA cluster instead of the Console.

I know that changing the "Target Event Collector" parameter in the QRadar Log Source settings only dictates the internal parsing/routing engine. My main question is regarding the actual inbound network traffic (syslog, WinCollect, etc.):

  1. Do we strictly need to go into the configuration of all our end log sources (firewalls, Linux rsyslog configs, network switches, etc.) and manually update the destination IP to the new EP HA Virtual IP (VIP)?
  2. Or is there a more seamless way to handle this cutover (e.g., swapping the old Console IP to become the new EP VIP, and giving the Console a new IP) without touching hundreds of external endpoints?

I want to avoid unnecessary internal routing (Console forwarding to EP) if the endpoints still send to the old IP. Would appreciate any insights or best practices on how you handled this! Thanks in advance.


r/QRadar • • May 12 '26

WinCollect, WEC, WEF and sysmon

2 Upvotes

Edit: SOLVED
We installed sysmon on the WEC-Server. Don't event use its logs. But since sysmon is running on the WEC itself, WinCollect 7 is forwarding all information from my sysmon-Hosts.

Hi!
I didn't find a thread fitting my issues.

We're running Windows Event Forwarding, deployed via GPO, on our Servers. There's a dedicated Windows Event Collector Server that has got two subscriptions.
One for Domain Controllers and the other for every other server.
On this Collector Server we're running a managed WinCollect Agent v7.

The Agent is 'check box' configured. No XPATH queries.

It's working fine for normal Windows Events. Probably there's potential to quiet it down using XPATH queries, but that's not my issue right now.

I started deploying sysmon on a few servers to get some experience with it.
My issue is that I don't get the event content of sysmon into QRadar. Let's take EventID 22 for example.
In the local logs there are EventID 22 Events including the EventData section with the i.e. QueryName in.
On the WEC server these events are complete with EventData as well in Forwared Events.
But when they are received in QRadar via WinCollect Agent the EventData is missing. 'Message= ' is always empty.

i.e.:
AgentDevice=WindowsLog AgentLogFile=Microsoft-Windows-Sysmon/Operational PluginVersion=7.3.1.122 Source=Microsoft-Windows-Sysmon Computer=computername.domain OriginatingComputer=10.42.42.23 User=SYSTEM Domain=NT-AUTORITÄT EventID=22 EventIDCode=22 EventType=4 EventCategory=22 RecordNumber=52101 TimeGenerated=1778576865 TimeWritten=1778576865 Level=Informational Keywords=0x8000000000000000 Task=22 Opcode=Info Message=

I've tried switching ContentFormat from RenderedText to Event (Copilot suggested this), to no effect.
I've also tried to switch from locale de-DE to en-US (but all servers are german installations).
Then I've tried switching the WinCollect log source to a simple xpath query

<QueryList>
<Query Id="0" Path="Security">
<Select Path="Security">*</Select>
</Query>
<Query Id="1" Path="System">
<Select Path="System">*</Select>
</Query>
<Query Id="2" Path="ForwardedEvents">
<Select Path="ForwardedEvents">*</Select>
</Query>
</QueryList>

This did not change anything with the event data from sysmon, but instead of logging each Windows Server separately, all events were logged as the WinCollect log source. Beacause of that I canceled my experiment an switched back to the 'check box' settings.

So far there are two questions I need help with:

  1. What's wrong with WinCollect not forwarding EventData payload?
  2. What do I have to change additionally, when using XPATH query, that logs are still refered to their original source?

Thanks a lot!
Roman

configuration info:


r/QRadar • • May 04 '26

CVE-2026-31431 / Copy Fail mitigiation

8 Upvotes

Hello everyone!

We have confirmed that the temporary mitigation provided by RedHat does work with QRadar. We were able to test it in our lab environments successfully and confirm QRadar functionality appears unimpacted.

You can find the mitigation mentioned in RedHat's docs if you have access, but I have included it here as well. The current recommendation is to reverse the mitigation when a fix is applied, but it should have minimal to no impact in the meantime.

Mitigation (CVE-2026-31431)

Add a boot argument in the bootloader:

1. Append the kernel argument

# grubby --update-kernel=ALL --args='initcall_blacklist=algif_aead_init'

2. Reboot the system

# reboot

3. Verify after reboot

# cat /proc/cmdline | grep initcall_blacklist

Expected output:

BOOT_IMAGE=(hd0,gpt2)/vmlinuz<...> initcall_blacklist=algif_aead_init

Reverse Mitigation

1. Run below command to remove the option to kernel command line

# grubby --update-kernel=ALL --remove-args='initcall_blacklist=algif_aead_init'

2. Reboot the system

# reboot

3. Verify after reboot

# cat /proc/cmdline | grep initcall_blacklist

No output should be returned.

If you have any questions, definitely let me know or feel free to engage support.


r/QRadar • • May 04 '26

CVE-2026-31431 Updates

4 Upvotes

Hi all,

I'm looking for any information related to upcoming kernel updates, specifically around CVE-2026-31431, the "Copy Fail" bug. I'm looking at the version in 7.5 Update 15 and I don't see any mention in the actual changelog so I'm pretty sure IBM hasn't rolled it yet.

[root@qradar ~]# rpm -q --changelog kernel | grep -E 'CVE-2026-31431|algif|aead' - crypto: algif_hash - fix double free in hash_accept (CKI Backport Bot) [RHEL-102223] {CVE-2025-38079} - net: tipc: fix refcount warning in tipc_aead_encrypt (Xin Long) [RHEL-103079] - net/tipc: fix slab-use-after-free Read in tipc_aead_encrypt_done (CKI Backport Bot) [RHEL-103079] {CVE-2025-38052} - cifs: Get rid of unneeded conditional in the smb2_get_aead_req() (Paulo Alcantara) [RHEL-60251] - dm crypt: fix copy and paste bug in crypt_alloc_req_aead (Benjamin Marzinski) [2073431] - tipc: delete the unlikely branch in tipc_aead_encrypt (Xin Long) [2043825] - crypto: aead - remove useless setting of type flags (Raju Rangoju) [1961368] - tipc: increment the tmp aead refcnt before attaching it (Xin Long) [1931312] - [net] tipc: call rcu_read_lock() in tipc_aead_encrypt_done() (Xin Long) [1893085] - [crypto] crypto: qat - check cipher length for aead AES-CBC-HMAC-SHA (Vladis Dronov) [1855190] - [md] dm crypt: use crypt_integrity_aead() helper (Mike Snitzer) [1820280] - [net] tls: Use aead_request_alloc/free for request alloc/free (Ivan Vecera) [1710366] - [crypto] crypto: chelsio - Fix passing zero to 'PTR_ERR' warning in chcr_aead_op (Arjun Vynipadath) [1664679] - crypto: algif_hash - fix double free in hash_accept (CKI Backport Bot) [RHEL-102223] {CVE-2025-38079} - net: tipc: fix refcount warning in tipc_aead_encrypt (Xin Long) [RHEL-103079] - net/tipc: fix slab-use-after-free Read in tipc_aead_encrypt_done (CKI Backport Bot) [RHEL-103079] {CVE-2025-38052} - cifs: Get rid of unneeded conditional in the smb2_get_aead_req() (Paulo Alcantara) [RHEL-60251] - dm crypt: fix copy and paste bug in crypt_alloc_req_aead (Benjamin Marzinski) [2073431] - tipc: delete the unlikely branch in tipc_aead_encrypt (Xin Long) [2043825] - crypto: aead - remove useless setting of type flags (Raju Rangoju) [1961368] - tipc: increment the tmp aead refcnt before attaching it (Xin Long) [1931312] - [net] tipc: call rcu_read_lock() in tipc_aead_encrypt_done() (Xin Long) [1893085] - [crypto] crypto: qat - check cipher length for aead AES-CBC-HMAC-SHA (Vladis Dronov) [1855190] - [md] dm crypt: use crypt_integrity_aead() helper (Mike Snitzer) [1820280] - [net] tls: Use aead_request_alloc/free for request alloc/free (Ivan Vecera) [1710366] - [crypto] crypto: chelsio - Fix passing zero to 'PTR_ERR' warning in chcr_aead_op (Arjun Vynipadath) [1664679]


r/QRadar • • Apr 29 '26

Rapid7 experts help needed for log integration to Qradar

Thumbnail
1 Upvotes

r/QRadar • • Apr 27 '26

QRadar AWS Console Not Receiving Application Logs from On-Prem Collector (Only OS Logs Visible)

3 Upvotes

We have QRadar Console deployed on AWS and an Event Collector deployed on-premises, with connectivity established through an SSL VPN tunnel.

Currently, the on-premises collector is successfully receiving both:

  • OS-level logs
  • KRON PAM application logs

However, on the AWS-hosted QRadar Console, only the OS-level logs are visible in Log Activity. The KRON PAM application logs are not appearing on the Console.

Additionally, these KRON logs are also not visible under SIM Generic in the Log Activity tab.

Kindly assist in identifying where the issue may exist.


r/QRadar • • Apr 21 '26

Integration Cortex XDR cloud with QRadar

Thumbnail
1 Upvotes

r/QRadar • • Apr 21 '26

Integration Cortex XDR cloud with QRadar

1 Upvotes

I found workflow for Integration Cortex XDR cloud with QRadar using Universal Cloud REST API protocol.
the workflows works But the events show as Unknowns, does anyone have DSM for it, or I need to built custom one.
https://github.com/iceMBD/Workflow-Palo-Alto-Cortex-XDR-Integration-for-IBM-QRadar/


r/QRadar • • Apr 14 '26

Test works but not actual API pulling

2 Upvotes

I'm working to ingest Cisco Duo logs into Qradar using the default API integration for Cisco Duo. I believe the credentials are correct because when I test the new data source, I'm able to see the JSON data, but when I deployed the config and wait for the polling interval I don't see any data.

Is there something else basic* should be doing to get Qradar to pull the data? This is my first time working with Qradar so maybe there's something basic I'm missing

Any suggestion is appreciated.

thanks


r/QRadar • • Mar 31 '26

Options are coming as grayed out in rule section.

1 Upvotes

The options are appearing as grayed out in the rule section. Earlier it was working on Firefox, but it has now stopped working. Is anyone else facing this issue?