IBM Security QRadar SOAR

 View Only
  • 1.  ISSUE with supper admin acount

    Posted Mon March 18, 2019 10:17 AM
    Hello,
    I had installed resilient and integrated him to AD and Qradar, my issue was apared when i mestakely deleted the Supper admin, but fortuntly i had an other acount with supper admin ( memeber of Active directoy) the issue is i should retore the admin supper, can you help me about how to working about the issue . thnak you

    ------------------------------
    Larbi Belmiloud
    ------------------------------


  • 2.  RE: ISSUE with supper admin acount

    Posted Mon March 18, 2019 11:16 AM
    To my knowledge, Resilient does not come with built-in users. Typically a "super user" is created during installation time. So the question to restore the user depends on whether or not the user was assigned to incidents or tasks and thus being used as a user that works with incident data.

    In any case, if you do want to restore the user you can do so using the resutil command line tool:

    newuser -email admin@yourorg.com -first Admin -last System -org 'orgname' -password 'thisismypassword'"

    This actually brings back the use with that email address.


    ------------------------------
    Ben Lurie
    ------------------------------



  • 3.  RE: ISSUE with supper admin acount

    Posted Tue March 19, 2019 07:40 AM
    hello Ben, 
    thank you for the response, the issue was after mestakelly i deleted un supper admin acount ( the acount used to lunch the fisrt time) fortunatly i had created an limited acount and used it with the commande below 

    resutilnewuser -email admin@yourorg.com -first Admin -last System -org 'orgname' 

    and i recovred my access as supper admin from the limited acount, now i will try to recover the access for the supperadmin with disply me that there was error on organisation desply profile .


    i will work around and comme back to . 
    thank you 


    ------------------------------
    Larbi Belmiloud
    Cyber Security IT
    intervalle technologies
    Algires
    ------------------------------



  • 4.  RE: ISSUE with supper admin acount

    Posted Thu March 21, 2019 06:01 AM
    hello all, 
    since we use Active directory as methode of athuntification, all users acounts need to be in the groupe we use in AD ( ldap) to be abel to connecte to resilient ( work space is the group we assined to ouar users) .
    Great job. 
    I'will happy to help any persone how had an issue.


    ------------------------------
    Larbi Belmiloud
    Cyber Security IT
    intervalle technologies
    Algires
    ------------------------------