IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  CRE logs unreadable after upgrade to QRadar UP13

    Posted Tue August 26, 2025 08:47 AM

    After upgrading to  UP13, the built-in log source "Custom Rule Engine-8 " started generating events with unreadable binary/unparsed payloads. These logs were not present before the upgrade and now create noise in Log Activity.

    What is the recommended solution or fix for this issue?



    ------------------------------
    Ökkes Güngör
    ------------------------------


  • 2.  RE: CRE logs unreadable after upgrade to QRadar UP13

    Posted Wed August 27, 2025 05:48 AM

    Adding comment to track this, as I noticed the same thing after applying the update in my lab (so I'm not alone :) ). 



    ------------------------------
    Dusan VIDOVIC
    ------------------------------



  • 3.  RE: CRE logs unreadable after upgrade to QRadar UP13

    Posted Wed August 27, 2025 08:00 AM

    Hi,

    if you mean something like this from "Custom Rule Engine-8":

    I agree, this seems to be "new" :( and also shows up with UP13 IF01.

    Regards,

    Ralph



    ------------------------------
    Ralph Belfiore
    Managing Consultant | SIEM Security Strategy & Data Resilience
    connecT SYSTEMHAUS AG
    Siegen
    ------------------------------



  • 4.  RE: CRE logs unreadable after upgrade to QRadar UP13

    Posted Wed August 27, 2025 08:17 AM

    For me it is a bit different (see image)

    ... and yes, same after IF01 has been applied.



    ------------------------------
    Dusan VIDOVIC
    ------------------------------



  • 5.  RE: CRE logs unreadable after upgrade to QRadar UP13

    Posted 23 days ago

    Ralph, were you able to track / resolve the cause of this behaviour? I still have the same unreadable stuff appearing after applying UP13IF02.



    ------------------------------
    Dusan VIDOVIC
    ------------------------------



  • 6.  RE: CRE logs unreadable after upgrade to QRadar UP13

    Posted 23 days ago

    Hey Dusan, nope.. I still can see a couple of those unusable stuff.. as well after UP13IF02 applied. Just a couple but some a day..

    Because of that less amount currently I just "ignore" them .. still :)

    Regards,

    Ralph



    ------------------------------
    Ralph Belfiore
    Managing Consultant | SIEM Security Strategy & Data Resilience
    connecT SYSTEMHAUS AG
    Siegen
    ------------------------------



  • 7.  RE: CRE logs unreadable after upgrade to QRadar UP13

    Posted 23 days ago

    Well, in my lab these unreadable "Stored" messages are rather intensive, so I am using Routing rules to drop them for now - but I would be quite undecided what to do if it were in some of my clients' environments.



    ------------------------------
    Dusan VIDOVIC
    ------------------------------