IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
Expand all | Collapse all

Deleting the WinCollect Directories from data base

  • 1.  Deleting the WinCollect Directories from data base

    Posted Fri November 19, 2021 01:33 AM
    Hi All, 

    I have installed 4 times Wincollect for my QRadar but those wincollect doesn't established connection with Qradar. Now I want to delete those wincollect directories from the Database through the command line interface of Qradar.
    Note: Not from the control panel and not from the Qradar console.
    Need the command to run from CLI of QRadar


    Thankyou

    ------------------------------
    Bilal Manzoor
    ------------------------------


  • 2.  RE: Deleting the WinCollect Directories from data base

    Posted Mon November 22, 2021 06:20 AM
    Bilal,

    unfortunately dont know about your Qradar background. Maybe you are quite desperate about your failing wincollect installs, which I can understand very well. However the command you are looking for wont help you anyway. Please enter wincollect as search keyword in discussion forum and you will find many trouble shooting information for command line on both sides to effectively get you nearer to the root cause of your problem.

    The other reason why you will probably never get an answer to your question is, that database architecture for wincollect is much too complex and release dependent too come up with something like what you are looking for. Some more background info on that: if you ask the database for sensor tables you receive min. 46 lines in release 7.3.3. All those tables depend on each other and are related using database views and thus there is no easy way to "delete" sensors other than deleting everything inside. The result would be an inconsistent and failing configuration. Not a good idea and nothing you would like to go for. The screenshot enclosed will give you an idea of sensor architecture inside database. Just my 0.2 cent.



    ------------------------------
    [Karl] [Jaeger] [Business Partner]
    [QRadar Specialist]
    [pro4bizz]
    [Karlsruhe] [Germany]
    [4972190981722]
    ------------------------------