IBM Security QRadar

 View Only
Expand all | Collapse all

Custom Rule is BB:CategoryDefinition: Authentication Failures : Not fetching results

  • 1.  Custom Rule is BB:CategoryDefinition: Authentication Failures : Not fetching results

    Posted Sun July 04, 2021 07:41 AM
    Dear Team
    We have been observing that  Custom Rule is BB:CategoryDefinition: Authentication Failures is not matching any of the low-level categories tagged events even if it's being triggered, because of this even reports for authentication failures are turning up empty, anyone has seen this before? any inputs would be highly appreciated.

    Empty results:

    Low-level category:

    Building block:

    T&R
    Arjun


    ------------------------------
    Arjun Kumar Network & Security Engineer
    ------------------------------


  • 2.  RE: Custom Rule is BB:CategoryDefinition: Authentication Failures : Not fetching results

    Posted Mon July 05, 2021 02:48 AM
    Update: The issue was resolved. The load building blocks rule was disabled.

    ------------------------------
    Arjun Kumar Network & Security Engineer
    ------------------------------