Hi, everyone.
I have the same error. I am trying to update it because it is a nightmare to integrate QRadar CE with Azure Event Hubs. It is timing out for no reason.
Manifest does not exist: HTTP 404
It seems to be all good here in terms of the certificate.
Sep 24 10:29:01 vw-op-qradarce-01 AUTOUPDATE[28911]: Autoupdate 8.9 initialized.
Sep 24 10:29:01 vw-op-qradarce-01 AUTOUPDATE[28911]: Do we need to turn on SSL Cert
Sep 24 10:29:01 vw-op-qradarce-01 AUTOUPDATE[28911]: SSl cert is set correctly
Sep 24 10:29:07 ::ffff:192.168.1.223 [masterdaemon.masterdaemon] [a8be2f23-1330-4696-bd5c-cf165429a8b2/SequentialEventDispatcher] com.ibm.si.ep.filters.EPEntryRoutingFilter: [INFO] [NOT:0000006000][192.168.1.223/- -] [-/- -]MPC Event Rate: 0 eps. Central Processing Event
Rate: 0 eps.
Sep 24 10:29:07 vw-op-qradarce-01 AUTOUPDATE[28911]: Could not retrieve "dau/dau.manifest.xml.asc": 404 Not Found
Sep 24 10:29:07 vw-op-qradarce-01 AUTOUPDATE[28911]: Could not retrieve signature for the manifest file.
The version:
The main issue is the Azure Event Hub configuration. It is timing out. And I can't understand the reason. The host where QRadar CE SIEM is deployed had all the access to it.
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] com.q1labs.semsources.sources.microsoftazureeventhubs.MicrosoftAzureEventHubsProvider: [ERROR] [NOT:0000003000][192.168.1.223/- -] [-/- -]Ensure that there are no network related issues pre
venting the connection. Additionally ensure that the Event Hub and Storage Account Connection Strings are valid.
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] java.util.concurrent.ExecutionException: com.microsoft.azure.eventhubs.IllegalEntityException: Failure getting partition ids for event hub
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at java.util.concurrent.CompletableFuture.reportGet(CompletableFuture.java:368)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at java.util.concurrent.CompletableFuture.get(CompletableFuture.java:1906)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at com.q1labs.semsources.sources.microsoftazureeventhubs.host.MicrosoftAzureEventHubsHostRunner.registerHost(MicrosoftAzureEventHubsHostRunner.java:112)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at com.q1labs.semsources.sources.microsoftazureeventhubs.host.MicrosoftAzureEventHubsHostRunner.start(MicrosoftAzureEventHubsHostRunner.java:119)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at com.q1labs.semsources.sources.microsoftazureeventhubs.MicrosoftAzureEventHubsProvider.preExecuteConfigure(MicrosoftAzureEventHubsProvider.java:79)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at com.q1labs.semsources.sources.base.SourceProvider.run(SourceProvider.java:181)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] Caused by: com.microsoft.azure.eventhubs.IllegalEntityException: Failure getting partition ids for event hub
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at com.microsoft.azure.eventprocessorhost.PartitionManager.lambda$cachePartitionIds$4(PartitionManager.java:80)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at com.microsoft.azure.eventprocessorhost.PartitionManager$$Lambda$72.00000000DC15DB90.apply(Unknown Source)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at java.util.concurrent.CompletableFuture.uniHandle(CompletableFuture.java:833)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at java.util.concurrent.CompletableFuture$UniHandle.tryFire(CompletableFuture.java:808)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at java.util.concurrent.CompletableFuture$Completion.run(CompletableFuture.java:453)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:522)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at java.util.concurrent.FutureTask.run(FutureTask.java:277)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.access$201(ScheduledThreadPoolExecutor.java:191)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.run(ScheduledThreadPoolExecutor.java:304)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1160)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:635)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at java.lang.Thread.run(Thread.java:812)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] Caused by: com.microsoft.azure.eventhubs.TimeoutException: Management request timed out on the client - enable info level tracing to diagnose.
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at com.microsoft.azure.eventhubs.impl.ManagementChannel$1.onEvent(ManagementChannel.java:64)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at com.microsoft.azure.eventhubs.impl.DispatchHandler.onTimerTask(DispatchHandler.java:12)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at org.apache.qpid.proton.engine.BaseHandler.handle(BaseHandler.java:233)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at org.apache.qpid.proton.engine.impl.EventImpl.dispatch(EventImpl.java:108)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at org.apache.qpid.proton.reactor.impl.ReactorImpl.dispatch(ReactorImpl.java:324)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at org.apache.qpid.proton.reactor.impl.ReactorImpl.process(ReactorImpl.java:291)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at com.microsoft.azure.eventhubs.impl.MessagingFactory$RunReactor.run(MessagingFactory.java:620)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] ... 7 more
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] com.q1labs.frameworks.naming.FrameworksNaming: [INFO] [NOT:0000006000][192.168.1.223/- -] [-/- -]Loaded singleton: NotificationLightDAO/com.q1labs.core.dao.notif.light.Notification/2362fca7
-2e58-4604-b2f3-7755ca91e4f9
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] com.q1labs.semsources.sources.microsoftazureeventhubs.MicrosoftAzureEventHubsProvider: [ERROR] [NOT:0070003100][192.168.1.223/- -] [-/- -]An error occured when trying to configure a source
connection for provider class com.q1labs.semsources.sources.microsoftazureeventhubs.MicrosoftAzureEventHubsProvider69
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] java.util.concurrent.ExecutionException: com.microsoft.azure.eventhubs.IllegalEntityException: Failure getting partition ids for event hub
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at java.util.concurrent.CompletableFuture.reportGet(CompletableFuture.java:368)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at java.util.concurrent.CompletableFuture.get(CompletableFuture.java:1906)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at com.q1labs.semsources.sources.microsoftazureeventhubs.host.MicrosoftAzureEventHubsHostRunner.registerHost(MicrosoftAzureEventHubsHostRunner.java:112)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at com.q1labs.semsources.sources.microsoftazureeventhubs.host.MicrosoftAzureEventHubsHostRunner.start(MicrosoftAzureEventHubsHostRunner.java:119)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at com.q1labs.semsources.sources.microsoftazureeventhubs.MicrosoftAzureEventHubsProvider.preExecuteConfigure(MicrosoftAzureEventHubsProvider.java:79)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at com.q1labs.semsources.sources.base.SourceProvider.run(SourceProvider.java:181)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] Caused by: com.microsoft.azure.eventhubs.IllegalEntityException: Failure getting partition ids for event hub
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at com.microsoft.azure.eventprocessorhost.PartitionManager.lambda$cachePartitionIds$4(PartitionManager.java:80)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at com.microsoft.azure.eventprocessorhost.PartitionManager$$Lambda$72.00000000DC15DB90.apply(Unknown Source)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at java.util.concurrent.CompletableFuture.uniHandle(CompletableFuture.java:833)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at java.util.concurrent.CompletableFuture$UniHandle.tryFire(CompletableFuture.java:808)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at java.util.concurrent.CompletableFuture$Completion.run(CompletableFuture.java:453)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:522)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at java.util.concurrent.FutureTask.run(FutureTask.java:277)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.access$201(ScheduledThreadPoolExecutor.java:191)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.run(ScheduledThreadPoolExecutor.java:304)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1160)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:635)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at java.lang.Thread.run(Thread.java:812)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] Caused by: com.microsoft.azure.eventhubs.TimeoutException: Management request timed out on the client - enable info level tracing to diagnose.
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at com.microsoft.azure.eventhubs.impl.ManagementChannel$1.onEvent(ManagementChannel.java:64)
Sep 24 10:08:50 ::ffff:192.168.1.223 [ecs-ec-ingress.ecs-ec-ingress] [Thread-1633] at com.microsoft.azure.eventhubs.impl.DispatchHandler.onTimerTask(DispatchHandler.java:12)
When I tried to install python 3.7 to write a simple consumer and verify deeply I got this:
For a Community Edition. This is a self-Learning environment, but I can't install tools.
[root@vw-op-qradarce-01 Python-3.7.11]# yum install python3
Loaded plugins: product-id, search-disabled-repos, subscription-manager
This system is not registered with an entitlement server. You can use subscription-manager to register.
No package python3 available.
Error: Nothing to do
------------------------------
Thiago Fonseca Born da Silva
------------------------------
Original Message:
Sent: Fri April 01, 2022 08:08 AM
From: Karl Jaeger
Subject: Can't update Qradar CE
have you checked for certificate errors in your system messages?
This tip might help:
https://www.ibm.com/support/pages/apar/IJ23059
------------------------------
[Karl] [Jaeger] [Business Partner]
[QRadar Specialist]
[pro4bizz]
[Karlsruhe] [Germany]
[4972190981722]
Original Message:
Sent: Tue March 29, 2022 10:35 AM
From: M. Offermann
Subject: Can't update Qradar CE
Any idea what it could be?
------------------------------
M. Offermann
Original Message:
Sent: Mon March 28, 2022 10:26 AM
From: Dusan VIDOVIC
Subject: Can't update Qradar CE
Not sure from the screenshot - make sure you have the trailing / in the webserver line https://auto-update.qradar.ibmcloud.com/
------------------------------
Dusan VIDOVIC
Original Message:
Sent: Mon March 28, 2022 09:52 AM
From: M. Offermann
Subject: Can't update Qradar CE
I tried that but it still doesn't work:
------------------------------
M. Offermann
Original Message:
Sent: Mon March 28, 2022 03:30 AM
From: Robert Karpiński
Subject: Can't update Qradar CE
Hello,
You have to to change update server. Please see details in following technote:
https://www.ibm.com/support/pages/qradar-important-auto-update-server-changes-administrators
Kind regards,
Robert
------------------------------
Robert Karpiński
Original Message:
Sent: Thu March 24, 2022 05:53 PM
From: M. Offermann
Subject: Can't update Qradar CE
Hello,
today I managed to install Qradar CE and all is working fine so far. Only problem is, that I can't auto-update.
[root@qradar ~]# /opt/qradar/bin/UpdateConfs.pl -testConnect 1 0
[AUTOUPDATE] [TESTCONNECT] Testing Internet Connection
[AUTOUPDATE] [TESTCONNECT] ------- Debug DownloadFile -------
[AUTOUPDATE] [WARN] Could not read company
[AUTOUPDATE] [DEVEL] Recorded license info as "?version=7.3.3&iv=2019.14.0.20191031163225&lastau=0&lastpatch=0&vendor=Q1%20Labs"
[AUTOUPDATE] [DEVEL] Downloading "manifest_list_512" and placing in "/store/autoupdates/".
[AUTOUPDATE] [TESTCONNECT] Verify ssl is turned on
[AUTOUPDATE] [DEVEL] Attempting to retrieve https://qmmunity.q1labs.com/autoupdates/manifest_list_512?version=7.3.3&iv=2019.14.0.20191031163225&lastau=0&lastpatch=0&vendor=Q1%20Labs
[AUTOUPDATE] [TESTCONNECT] AU Proxy server setting - no proxy settings found
-----------------Summary-----------------
[AUTOUPDATE] [TESTCONNECT] PERL_LWP_SSL_VERIFY_HOSTNAME: 1
[AUTOUPDATE] [TESTCONNECT] PERL_NET_HTTPS_SSL_SOCKET_CLASS: IO::Socket::SSL
[AUTOUPDATE] [TESTCONNECT] Proxy Server:
[AUTOUPDATE] [TESTCONNECT] Status Line: 500 Can't connect to qmmunity.q1labs.com:443
[AUTOUPDATE] [TESTCONNECT] Content Line:
Can't connect to qmmunity.q1labs.com:443
Connection refused at /usr/share/perl5/LWP/Protocol/http.pm line 51.
-----------------------------------------
[AUTOUPDATE] [WARN] Could not retrieve "manifest_list_512": 500 Can't connect to qmmunity.q1labs.com:443
[AUTOUPDATE] [TESTCONNECT] Could not download manifest list.
I double checked the firewall logs (Pfsense) and I found no firewall deny/block event for Qradar.
I do not use any kind of proxy configuration.
Qradar is installed as a Proxmox VE KVE-VM. Qradar has a static public IP and LAN IP to use, 256GiB drive and 10 GB RAM with 6 CPUs.
If you need any more info about my deployment let me know.
Can anybody help me with this?
------------------------------
M. Offermann
------------------------------