IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  IBM QRadar Node License Issue

    Posted 7 hours ago

    Dear Team,

    I installed event collector and on event collector tcp 514 is not listening when i did the netstat and i believe all my 22 node licenses are consumed. Now i want to delete one old event collector and want to assign that event collector node license to the new event collector. Please let me know if i remove that event collector from console then the node license will free up automatically or i have to clear from backend and if yes then what will be the steps to cleanup from backend and free that node license.Please help me with immediate support.

    Regards

    Hamdan Shakeel



    ------------------------------
    Hamdan Shakeel
    ------------------------------


  • 2.  RE: IBM QRadar Node License Issue

    Posted 7 hours ago

    Hi Hamdan

    Is the EC listening on 514 for UDP?  If so do you have any TCP syslog logsources defined for that EC?

    Are there any logs coming to the console for the EC?  Has the EC been added to the deployment and connected to a console or EP?

    Thanks



    ------------------------------
    John Dawson
    Qradar Support Architect
    IBM
    ------------------------------



  • 3.  RE: IBM QRadar Node License Issue

    Posted 6 hours ago
    Edited by Hamdan Shakeel 6 hours ago

    Hi John,


    The collector is successfully added to the console and it's showing active in console. I am trying to send logs from my windows machine but its showing connection failed for the tcp 514. This is the output i am receiving when i am doing netstat on collector.

    [root@ec1 ~]# netstat -nlp | grep 514
    tcp6       0      0 :::1514                 :::*                    LISTEN      27966/syslog-ng
    udp6       0      0 :::514                  :::*                                20641/java
    udp6       0      0 :::1514                 :::*                                27966/syslog-ng
    unix  2      [ ACC ]     STREAM     LISTENING     1395514  26639/master         private/discard
    [root@ec1 ~]#



    ------------------------------
    Hamdan Shakeel
    ------------------------------