IBM Security QRadar

 View Only
  • 1.  Monitor Console and EC connectivity

    Posted Fri October 11, 2019 11:31 AM
    Hi,
    Is there a rule/logic to monitor connectivity between console and collector? without using QID?

    thanks.

    ------------------------------
    Hemant Kumar
    ------------------------------


  • 2.  RE: Monitor Console and EC connectivity

    Posted Tue October 29, 2019 11:03 AM
    Hi @Hemant Kumar,

    I would like to understand more on what you want to monitor. Do you want just network level monitoring or application level as well. 
    If it is application level i.e. the services communicating with each other, which is a bit tricky, you can create custom scripts where it checks services status and alert on when the service hangs or stops.

    ------------------------------
    Chinmay Kulkarni
    ------------------------------



  • 3.  RE: Monitor Console and EC connectivity

    Posted Tue October 29, 2019 04:14 PM
    I could be interested in this as well.  With a distributed deployment, a "Host Down" alert could be very valuable.

    ------------------------------
    Paul Goffar
    ------------------------------



  • 4.  RE: Monitor Console and EC connectivity

    Posted Wed October 30, 2019 05:02 AM
    I would be intrested but what has stopped me in the past is that the managed hosts utilise the console as a ssylog server - thus when an outage occurs the managed hosts havent got a way of informing the console they are down. A case of chicken and egg.

    This has led me to belive that an agent on the managed host would be needed.


    ------------------------------
    James Hill
    ------------------------------



  • 5.  RE: Monitor Console and EC connectivity

    Posted Wed October 30, 2019 10:09 AM
    Here are the two options which I got, Need to validate though.

    1- (colleague advised) Every device will have com.q1labs.configservices.controller.ServerHostStatusUpdater class which will send update whether it is active or not

    2- (found this online) "you can create an AQL query to filter information events from the "system notifications" log source. I don't have the exact query on me at the time of writing but you can search for the term "UNKOWN" narrow it down from there. After you have your AQL query, create a rule with it and another test "This many events with same property in this many mins". Tune it to your liking and now you ave an offense on a collector going down."

    ------------------------------
    Hemant Kumar
    ------------------------------



  • 6.  RE: Monitor Console and EC connectivity

    Posted Wed October 30, 2019 09:28 AM
    This should help you to notify any connectivity issues between console and managed host - Process Monitor: Application has failed to start up multiple times

    You can also create rules based on its QID, with rule response for email notification with your ITSM solution also.

    ------------------------------
    3 b
    ------------------------------