IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  uDSM Parsing

    Posted Thu November 12, 2020 10:02 PM

    I have parsed all fields in a uDSM custom parser and they appear correctly in the DSM Editor, but for one Event ID only i am seeing Unknown as the Event Type/Category while all others are getting parsed correctly. For this Unknown event in the DSM Editor it is showing as Parsed and Mapped but still it shows Unknown. Kindly can someone help.



    #QRadar
    #Support
    #SupportMigration


  • 2.  RE: uDSM Parsing

    Posted Wed November 18, 2020 12:31 PM

    Hi Muhammad ,Abraham here.

    Iv used the DSM Editor significantly,iv experienced such a thing as well.

    The first thing I did is verify that the Regex captures the specific event on the DSM editor(The event is highlighted)

    If this is so verify that the event ID U used during the mapping is a valid event ID and event category otherwise it won't parse it.

    If the event ID and category is valid delete the mapping and create a new one on the DSM editor.

    If this doesnt work open a case with IBM, hope this helps



    #QRadar
    #Support
    #SupportMigration


  • 3.  RE: uDSM Parsing

    Posted Wed December 02, 2020 08:43 PM

    I did encounter cases when the usual way of creating an exact Event ID / QID reference would not automatically map the event. Not sure if you already did that, but in such cases I the old-fashioned way of opening the event and using the Map Event option helped.

    If this is something you already tried, I am curious if you found maybe reference to similar problems in APARs or so (this mostly version specific).



    #QRadar
    #Support
    #SupportMigration