IBM Security MaaS360

 View Only
  • 1.  Account for connecting MaaS360 as a logsource to QRadar.

    IBM Champion
    Posted Tue March 17, 2020 01:30 PM
    In MaaS360 I would need to create an account that does not expire the password so I can use it to connect the MaaS360 as a logsource to QRadar.

    If I create an account with the settings below, it will likely expire the password after some time.
    An error is displayed in the QRadar MaaS360 settings logsource "Error - Unable to login to IBM Fiberlink REST API!"

    The account used has the following roles:
    Administrator
    Administrator - Level 2
    Portal Administrator
    Read-Only
    Service Administrator

    How to properly create a MaaS360 account for this purpose?

    ------------------------------
    Martin Hansgut
    ------------------------------


  • 2.  RE: Account for connecting MaaS360 as a logsource to QRadar.

    IBM Champion
    Posted Mon March 23, 2020 12:10 PM
    Have the admin account conditions changed recently? I set a new password, but I'm still getting an error "ERROR - Unable to login to IBM Fiberlink REST API!".

    Can you tell me what to check?

    ------------------------------
    Martin Hansgut
    ------------------------------



  • 3.  RE: Account for connecting MaaS360 as a logsource to QRadar.

    Posted Tue March 24, 2020 11:59 AM

    Hi Martin,

    Can you reach out to me via email and I'll help you debug - I'll need to look up your account data - mshaver@us.ibm.com



    ------------------------------
    Matt Shaver
    System Architect
    IBM
    mshaver@us.ibm.com
    ------------------------------



  • 4.  RE: Account for connecting MaaS360 as a logsource to QRadar.

    Posted Mon June 21, 2021 08:45 AM
    Hello Martin, I am facing the same error if you can help me regarding that.

    ------------------------------
    Raheel Asim
    ------------------------------



  • 5.  RE: Account for connecting MaaS360 as a logsource to QRadar.

    IBM Champion
    Posted Tue August 31, 2021 05:58 PM
    Edited by Martin Hansgut Tue August 31, 2021 06:00 PM
    Hello Raheel,
    the account type must be "script only" to prevent password expiration. Furthermore, the MaaS360 certificate which is in QRadar must be in DER format and must not be expired.

    ------------------------------
    Martin Hansgut
    ------------------------------



  • 6.  RE: Account for connecting MaaS360 as a logsource to QRadar.

    IBM Champion
    Posted Fri August 12, 2022 07:22 AM
    Edited by Martin Hansgut Fri August 12, 2022 07:23 AM
    Once again, I got to the state where LogSource MaaS360 gives me the error "Error - Unable to login to IBM Fiberlink REST API!"

    Uploading a new certificate helped last time, but this time I'm not doing well or I'm making a mistake somewhere.

    I proceeded as follows:
    • I downloaded the certificate from the URL https://services.m2.maas360.com
    • Apparently the certificate is in DER format, but the file has a .cer extension, so I renamed it to .der.
    • I copied the certificate file to the directory /opt/qradar/conf/trusted_certificates
    • I didn't take any further steps.

    Did I forget something?

    ------------------------------
    Martin Hansgut




  • 7.  RE: Account for connecting MaaS360 as a logsource to QRadar.

    Posted Mon August 15, 2022 12:52 AM
    After the account has been created, you need to contact Maas360 support and request that they convert it to a service account. That way the password doesn't expire.

    ------------------------------
    Enrique Ruiz
    Mobile Platform Engineer
    The Church of Jesus Christ of Latter Day Saints
    8012407034
    ------------------------------



  • 8.  RE: Account for connecting MaaS360 as a logsource to QRadar.

    IBM Champion
    Posted Mon August 15, 2022 02:37 AM
    Edited by Martin Hansgut Mon August 15, 2022 02:37 AM
    I made the transfer to the service account and the communication was functional. I have a problem since the certificate for communication with QRadar expired and it is necessary to upload a new one. I downloaded the certificate from the provided URL, copied it to the directory on QRadar, but the error still occurs.

    ------------------------------
    Martin Hansgut
    ------------------------------



  • 9.  RE: Account for connecting MaaS360 as a logsource to QRadar.

    Posted Mon August 15, 2022 04:13 AM
    Hi Martin
    Support will be able to create a key for your WebServices usage specifically for the Q-Radar integration. 
    Please contact them to request this. 
    Best

    ------------------------------
    Eamonn O'Mahony
    Technical Client Success Manager
    IBM Security
    Dublin, Ireland
    ------------------------------