IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  One of users in UBA recognize like more other users.

    Posted Wed September 11, 2019 05:31 AM

    Hello.

    I need your help for resolving this problem:
    In Qradar UBA we have one user with great score. This user recognize by UBA like many other users. Detailed information is on screen.



    Thank you.



    ------------------------------
    Vadim Novikov
    SOC Engineer
    IT-Specialist
    Kiev
    +380972970792
    ------------------------------


  • 2.  RE: One of users in UBA recognize like more other users.

    Posted Fri October 25, 2019 08:19 AM
    Hi @Vadim Novikov,
    The first thing I can think of is the coalescing os users. Normally when users are coalesced on an identity which is duplicate. For example Employee A and Employee B have different employee id, email address etc but same department. When you import information from LDAP you need to coalesce them on employee id and email address and not department. If you do on department all users in the department will be shown as one.

    So do this:
    In the UBA configuration, under coalescing, see if you are coalescing on an identity which can be duplicate. The UBA app will normally tell you (with an exclamation mark inside a triangle with yellow) to show that you have duplicates.
    Hope this helps.​

    ------------------------------
    Chinmay Kulkarni
    ------------------------------



  • 3.  RE: One of users in UBA recognize like more other users.

    Posted Thu November 07, 2019 03:18 PM
    Vadim:

    This is due to the coalescing field/fields chosen has over lapping entry i.e. one field has multiple values that points to different users.
    an example of that will be dept. code...if you pick the dept code as a field to coalesce users by, then ALL the people working in that dept. will be coalesced into a single user.

    Goto the UBA Setting page in the user coalesce section (about half way down that page) see the fields that you have chosen (checkmark) to coalesce users... the field that has this multiple overlapping value will be identified by an "!" mark next to it..uncheck that field and save and exit. In about 24 hours this problem should correct itself. hope it helps. Milan

    ------------------------------
    PATEL MILAN
    IBM
    ------------------------------