IBM QRadar SOAR

IBM QRadar SOAR

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  playbook execution stucks to plugin apps functions (no errors)

    Posted Fri March 29, 2024 07:01 PM

    Hello,

    I'm facing an issue that i meet for default playbooks (very simple one that comes by default with the app configured).

    The behaviour that i meet is for all plugin apps: abuseIPDB, MISP, artefact utilitis functions, Virus total (only those were tested) 

    The playbooks exécution keeps stuck on the fonction execution of the apps. It doesn't produce any errors i don't know where to look in order to see why it's taking such a long time (<30 min) for simple tasks (ex: add a tag to an artifact) 

    Any help would be appreciate,

    Thanks 



    ------------------------------
    Nicolas Pelletier
    ------------------------------


  • 2.  RE: playbook execution stucks to plugin apps functions (no errors)

    Posted Mon April 01, 2024 08:27 AM

    Hi Nicolas - can you confirm that the apps are all deployed and running? If so, can you confirm that they passed the configuration test when you installed them? It is likely that they have a configuration issue or a connectivity issue that is preventing them from picking up and completing the functions.



    ------------------------------
    Bo Bleckel
    ------------------------------



  • 3.  RE: playbook execution stucks to plugin apps functions (no errors)

    Posted Mon April 01, 2024 10:18 AM

    Hello Bo bleckel,

    Thanks for your help, i confirm that the app is running deployed and when i download logs from the app just after running the playbook execution i get no errors just the pod status. 

    However, when i launch the test configuration, this one keeps running without ending but no infos is provided. so i don't know if there is something wrong with it. 

    Best regard,

    Nicolas Pelletier 



    ------------------------------
    Nicolas Pelletier
    ------------------------------



  • 4.  RE: playbook execution stucks to plugin apps functions (no errors)

    Posted Mon April 01, 2024 10:30 AM

    Ah - that is likely then a configuration issue. You say that you have the app running, with logs looking good, but are those in fact real time logs? Are you willing to share you app.config file (please omit any sensitive information)? If so, I can take a look to determine if something is misconfigured. In most cases like this, it is an issue with the certificate (cafile config) or the api key



    ------------------------------
    Bo Bleckel
    ------------------------------



  • 5.  RE: playbook execution stucks to plugin apps functions (no errors)

    Posted Mon April 01, 2024 11:59 AM

    Ah thanks,

    Yes Indeed i think it's a cafile issue as it's set to cert.cer but this one is not configured. I change it to false and now the test succeed. 

    Thanks a lot, it's somehow a bit pity that no errors comes up during the test of the config. As it keeps running for hours without giving anything of what happend nor advice to look for...

    Thanks again

    Best regard



    ------------------------------
    Nicolas Pelletier
    ------------------------------



  • 6.  RE: playbook execution stucks to plugin apps functions (no errors)

    Posted Mon April 01, 2024 12:44 PM

    Fantastic, great to hear that that worked.

    I completely agree. We internally are working on an update for exactly that: get more information quicker on configuration test failures. That should be pushed out in the coming months 



    ------------------------------
    Bo Bleckel
    ------------------------------