IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Qradar Asset profile

    Posted Thu September 07, 2023 01:17 PM

    Hi, 

    my asset profil  operating system field is not filled while the logs contains the operating system of the asset.

    I would like to  know the way of automatically updating the asset profile.

    Thanks 



    ------------------------------
    Benjamin Yabre
    ------------------------------


  • 2.  RE: Qradar Asset profile

    Posted Mon September 11, 2023 05:03 AM

    Benjamin,

    when your logs contain OS info, you can extract that into a customfield "myserveros" and add it to your loc activity search. The OS information in the asset db is put in by vis service which takes security scanner report information from nessus and other tools and syncs those information with asset database.

    BR

    Karl



    ------------------------------
    [Karl] [Jaeger] [Business Partner]
    [QRadar Specialist]
    [pro4bizz]
    [Karlsruhe] [Germany]
    [4972190981722]
    ------------------------------



  • 3.  RE: Qradar Asset profile

    Posted Mon September 11, 2023 12:22 PM

    Hi Karl,

    thanks for your reply.

    it means that without securit scanner report there is no way of getting those information in the asset DB ?

    thanks



    ------------------------------
    Benjamin Yabre
    ------------------------------



  • 4.  RE: Qradar Asset profile

    Posted Wed September 13, 2023 02:45 AM

    Benjamin 

    I suggested Scanner as it is the easiest way to fill in the OS info, e.g. using nmap. As many orgs have CMDB info available the alternative is to import this info from there using the API. Using python for that purpose we made good experience. 
    BR Karl 



    ------------------------------
    [Karl] [Jaeger] [Business Partner]
    [QRadar Specialist]
    [pro4bizz]
    [Karlsruhe] [Germany]
    [4972190981722]
    ------------------------------