IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Flash Notice: SIM Generic events with IPv4/IPv6 header issue reported

    Posted Thu January 30, 2025 02:25 PM
    Edited by Jonathan Pechta Mon February 03, 2025 11:10 AM

    I'm raising visibility to an issue that support is tracking related to the SIM Generic log source. A flash notice was issued where SIM Generic log sources (the catch all bucket when events do not match a specific DSM) can drop events unexpectedly. There is an existing workaround for this issue, but support is encouraging all admins to confirm their version of SIM Generic on the Console, and if they have the affected version to downgrade the RPM. A flash notice was released by support for this specific issue.

    Notice: An updated SIM Generic DSM is available to resolve the dropped events issue for all users. Administrators can download the latest version of SIM Generic to the Console appliance from IBM Fix Central: SIMGenericLog-7.5-20250130145444.noarch.rpm.


    What to do:

    1. Review the technical note associated to this issue: QRadar: Unknown log events which have IPv4 or IPv6 in the syslog header that would be associated with the SIM Generic logsource are being dropped.

    2. If the reported version is: SM-SIMGenericLog-7.5-20241220124142 then you should complete the workaround to download the latest RPM. If you are on any other version, then you are not affected. The issue is specific to build 20241220124142.

    3. As this issue is a DSM issue, all users at 7.5.0 can be affected so review your current SIM Generic version to verify if you are affected. 

    If you have concerns or questions, you can ask here or contact QRadar Support for direct help.



    ------------------------------
    Jonathan Pechta
    IBM Security - Community of Practice Lead
    jonathan.pechta1@ibm.com
    ------------------------------



  • 2.  RE: Flash Notice: SIM Generic events with IPv4/IPv6 header issue reported

    Posted Fri January 31, 2025 04:07 AM

    Hi


    The workaround it's not really working like this in default configuration

    yum downgrade DSM-SIMGenericLog-7.5-20241204152906.noarch.rpm
    Loaded plugins: product-id, search-disabled-repos, subscription-manager

    This system is not registered with an entitlement server. You can use subscription-manager to register.

    There are no enabled repos.



    ------------------------------
    Stefano Pasa
    ------------------------------



  • 3.  RE: Flash Notice: SIM Generic events with IPv4/IPv6 header issue reported

    Posted Fri January 31, 2025 05:25 AM

    The workaround document seems to miss out the step where you need to download the 'old' DSM rpm from FixCentral and put it in your current directory before running the 'yum downgrade'

    # yum downgrade DSM-SIMGenericLog-7.5-20241204152906.noarch.rpm
    Can not load RPM file: DSM-SIMGenericLog-7.5-20241204152906.noarch.rpm.
    Error: No packages marked for downgrade.

    but it works with the file: DSM-SIMGenericLog-7.5-20241204152906.noarch.rpm is present.

    Paul



    ------------------------------
    Paul Ford-Hutchinson
    ------------------------------



  • 4.  RE: Flash Notice: SIM Generic events with IPv4/IPv6 header issue reported

    Posted Fri January 31, 2025 09:51 AM

    Paul

    thx a lot. While working on my DSMedit BLOG article I ran into this. Downgrade went fine.

    Regards

    Karl



    ------------------------------
    [Karl] [Jaeger] [#ibmchampion]
    [QRadar Specialist]
    [cnag]
    [Siegen] [Germany]
    ------------------------------



  •   5.  RE: Flash Notice: SIM Generic events with IPv4/IPv6 header issue reported
    Best Answer

    Posted Mon February 03, 2025 11:09 AM
    Edited by Jonathan Pechta Mon February 03, 2025 11:16 AM

    Notice: An updated SIM Generic DSM is available to resolve the dropped events issue for all users. Administrators can download the latest version of SIM Generic to the Console appliance from IBM Fix Central: SIMGenericLog-7.5-20250130145444.noarch.rpm.

    The associated flash notice was updated to change the instructions to yum -y install and users can install the latest SIM Generic RPM on the Console to resolve this issue. An RPM downgrade is no longer required, just install the latest. The Flash Notice associated to this issue can be found here: https://www.ibm.com/support/pages/node/7182076

    ------------------------------
    Jonathan Pechta
    IBM Security - Community of Practice Lead
    jonathan.pechta1@ibm.com
    ------------------------------



  • 6.  RE: Flash Notice: SIM Generic events with IPv4/IPv6 header issue reported

    Posted Tue February 04, 2025 06:57 AM

    There are some typo in the Flash Notice:

    You need to run "yum -y install DSM-SIMGenericLog-7.5-20250130145444.noarch.rpm" instead of "yum -y install SIMGenericLog-7.5-20250130145444.noarch.rpm"

    And you need to add -C to all_server command to run on Console (or on all in one) also like this: "

    /opt/qradar/support/all_servers.sh -k -C "systemctl restart ecs-ec"

    "



    ------------------------------
    Tamás Simon
    ------------------------------



  • 7.  RE: Flash Notice: SIM Generic events with IPv4/IPv6 header issue reported

    Posted 2 days ago
    ChatGPT said:

    Your site offers a clear, focused place for users to complete SIM card registration in the Philippines. It simplifies the process by guiding visitors through the required fields and documentation.Good layout and straightforward instructions can really help reduce user confusion and support requests. Consider adding FAQs and a contact/help option for edge cases or verification issues. Visit tnt sim registration link to see the live workflow and test the user experience.



    ------------------------------
    Chase Blitz
    ------------------------------