QRadar development has recently identified a defect in the product licensing function, which may cause the deployment to stop functioning. An emergency fix is available for all supported QRadar versions to resolve this issue. The issue is related to the function that validates a license key and is not related to the reported SolarWinds security issue.
A flash notice was issued to all users about the license error for services that report a "Waiting for license..." message in the logs. A recent update to the technical note includes a new single-line command that can be run on all QRadar versions at 7.2.8 and later. Even if you received an updated JAR file from QRadar Support, you must run the command on your QRadar Console. The command only needs to be run on the QRadar Console and it will update all remote appliances using the all_servers utility. It is important that administrators SSH to their Console appliances and run the one-line command to update all appliances in the deployment.
Administrators at all QRadar versions must run the command in the flash notice: https://www.ibm.com/support/pages/node/6395080
Note: The command must be run, even if you are on QRadar Community Edition. QRadar on Cloud users are received this update from their DevOps team already for your QRadar Console.
------------------------------
Jonathan Pechta
QRadar Support Content Lead
jonathan.pechta1@ibm.com
------------------------------