IBM Security QRadar SOAR

 View Only
  • 1.  Issue with App resilient to connecte from qradar to resilient

    Posted Wed May 08, 2019 09:02 AM
    hello, any baudy can help me about this issue! 
    the probleme is when we tried to reconnecte ( it meanse that we did it before and it works) appreislient to resileint augian, we gotted the error:  below in the 
    error qradar connection with resilient  can any baudy tell me about the origing of the probleme.

    ------------------------------
    [Larbi] [Belmiloud]
    [Cyber Security]
    [Intervalle Technologies]
    [Algers] [Algeria]
    [+213551193200]
    ------------------------------


  • 2.  RE: Issue with App resilient to connecte from qradar to resilient

    Posted Wed May 08, 2019 11:09 AM

    Hi Larby,

    A couple quick questions:

    1. Are your QRadar and Resilient platforms local, are they SaaS? 

    2. were there any changes to the topology between?

    thanks and let me know,
    Charlie



    ------------------------------
    Charlie Niemi MSIA, CISSP
    CTP, IBM Resilient.
    ------------------------------



  • 3.  RE: Issue with App resilient to connecte from qradar to resilient

    Posted Thu May 09, 2019 04:21 AM
    Hi,

    As a protection mechanism Resilient will ban (block) further attempts to authenticate from an IP address which tries to unsuccessfully authenticate a certain number of times. It will block that IP for a period of time which will increase in length the more times it fails to authenticate to avoid brute force attacks.

    I believe you raised a ticket with Customer Success and a colleague responded with details of how to remove the banned IP. You should check all integrations that are using the banned username from the banned IP address to ensure you have the correct password.

    ------------------------------
    BEN WILLIAMS
    ------------------------------



  • 4.  RE: Issue with App resilient to connecte from qradar to resilient
    Best Answer

    Posted Thu May 09, 2019 04:49 AM
    Thank you Ben, 
    effectivelly the issue was that resilient Baned my App IP , sow the solution is below: 

    1. Run the following command to confirm there's an IP banned:

    sudo -u postgres psql -c "select * from monapp.ipban;" co3

    2. Remove the banned IP by running command:

    sudo -u postgres psql -c "delete from monapp.ipban;" co3

    3. Restart Resilient service by command:

    sudo systemctl restart resilient (for RHEL system)


    that's all. 

    hope to help other

    ------------------------------
    [Larbi] [Belmiloud]
    [Cyber Security]
    [Intervalle Technologies]
    [Algers] [Algeria]
    [+213551193200]
    ------------------------------