IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Use UBA LDAP reference table (UBA_Default) in event rules

    Posted Fri September 13, 2019 06:43 AM
    Hello

    I would like to know if it is possible to use in event rules the reference table where my users are imported from LDAP to be used in UBA. I want to create a rule that search if username in events matches with any of my user from my Active Directory, but when I try to add UBA LDAP (UBA_Default) users reference table in the rule condition, this reference table is not available. Is there any way to use this table or to search in events my Active Directory users imported?

    Thanks in advanced

    ------------------------------
    ACG
    ------------------------------


  • 2.  RE: Use UBA LDAP reference table (UBA_Default) in event rules

    Posted Fri September 13, 2019 07:29 AM

    Hello)

    Yes it is possible. I`m use this BB when create rules:



    ------------------------------
    Vadim Novikov
    SOC Engineer
    IT-Specialist
    Kiev
    +380972970792
    ------------------------------



  • 3.  RE: Use UBA LDAP reference table (UBA_Default) in event rules

    Posted Tue September 17, 2019 04:24 AM
    Hello Vadim

    I've tried to use that type of rule, but when I'm going to select the "reference table key", UBA_Default is not available to select in the list. I can select others like "Anonymizer IPs Data --> PRIMARY_KEY" or "Botnets IPs Data --> PRIMARY_KEY". Why Can't I select UBA reference table?

    Thanks in advanced

    ------------------------------
    A CG
    ------------------------------



  • 4.  RE: Use UBA LDAP reference table (UBA_Default) in event rules

    Posted Fri June 05, 2020 10:59 AM

    Hi!

    Could you solve this problem? I have a similar one.

    Greetings
    Bruno



    ------------------------------
    Bruno Oliveira
    ------------------------------



  • 5.  RE: Use UBA LDAP reference table (UBA_Default) in event rules

    Posted Fri September 13, 2019 07:36 AM

    But you should know that some data in this table is dynamical !

    Be careful with rules.



    ------------------------------
    Vadim Novikov
    SOC Engineer
    IT-Specialist
    Kiev
    +380972970792
    ------------------------------