Hi John,
the Source IPv6 is always 0:0:0:0:0:0:0:0. Some of those events have IP addresses in the message part, but not in the Syslog header. I also found some events where the Source IP is correct, in that case the Log Source Identifier is the same IP address. The events without a proper Source IP have a Log Source Identifier which is not an IP address.
Before the update all events had a proper Source IP, regardless of the Log Source Identifier.
According to the release notes of UP 10, a feature added was "IPv6 addresses in syslog headers can now be parsed for Log Source IDs.". Maybe this change affected how the Source IP is set?
Best regards
Simon
------------------------------
Simon S.
------------------------------
Original Message:
Sent: Fri October 25, 2024 04:57 AM
From: John Dawson
Subject: Events in SIM Generic Log DSM have Source IP 0.0.0.0 after UP 10 Update
HI Simon,
Do these events have an IPv6 address? Also do these events have a source IP set in the payload?
What was the behaviour prior to UP10?
Thanks
------------------------------
John Dawson
Qradar Support Architect
IBM
Original Message:
Sent: Wed October 23, 2024 03:33 AM
From: Simon S.
Subject: Events in SIM Generic Log DSM have Source IP 0.0.0.0 after UP 10 Update
Hi everyone,
I have installed UP 10 on our test system and I noticed that all events in the SIM Generic Log DSM have Source IP 0.0.0.0. On our production system on UP 9 IF 03 all the events there have the sending system's IP as Source IP (as described here).
I use the Source IP to identify where the events are coming from, especially with malformed events that do not provide any other useful information.
Did anyone else notice this behaviour as well?
Best regards
Simon