IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Migrating rules and dependencies from an All-In-One to a distributed environment?

    Posted Sun May 26, 2024 05:41 AM
    Edited by V 2018 Thu August 22, 2024 01:09 PM

    Hi all,

    has anyone tried to migrate rules, BBs (and dependencies) from an All-In-One to a distributed environment?

    Any thoughts on feasibility, what to watch out for (filesystem-level permissions which may be different?) etc. would be greatly appreciated.

    There are a few docs available on how this should work (by using the CMT tool etc.), however I`d still like to hear real world experiences... :)

    Many thanks in advance!



  • 2.  RE: Migrating rules and dependencies from an All-In-One to a distributed environment?

    Posted Mon May 27, 2024 07:00 AM

    Hi Vedran

    Jose Bravo has a series of videos on this

    https://www.youtube.com/watch?v=MBoaYUZCnZQ

    There should be no differebce in filesystem-level permissions.

    You may also need to consider any CEP's used in the rules/BB's which are being migrated.

    Thanks



    ------------------------------
    John Dawson
    Qradar Support Architect
    IBM
    ------------------------------



  • 3.  RE: Migrating rules and dependencies from an All-In-One to a distributed environment?

    Posted Mon May 27, 2024 08:03 AM
    Edited by V 2018 Thu August 22, 2024 01:37 PM

    Hi John,

    thanks a lot - I'll certainly have a look at Jose's videos once again!

    Meanwhile, while executing the following command on my testing environment: 

    ./contentManagement.pl --action export -c all

    I got dozen of "[INFO] Found a search that is pertaining to the Retention Policy. We currently and temporarily do not support export or import of that content as a better solution from the ground up is scheduled to worked on very soon." errors back.

    Any workaround (and/or an explanation) for this?

    Thanks again,

    kind regards



    ------------------------------
    Vedran Zulin
    ------------------------------



  • 4.  RE: Migrating rules and dependencies from an All-In-One to a distributed environment?

    Posted Tue May 28, 2024 04:43 AM

    It just means that searches which are used for Retention buckets will not be exported (and therefore not imported).  You will need to re-create Retention bucket settings manually on the target system if required.

    pfh



    ------------------------------
    Paul Ford-Hutchinson
    ------------------------------