IBM QRadar SOAR

IBM QRadar SOAR

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  QRadar Enhanced Data Migration - QRadar Offense Summary

    Posted Wed March 01, 2023 10:03 AM

    Hi,

     I was testing the QRadar Enhanced Data Migration application and more specifically the QRadar Offense Summary function, for some reason it is not updating my fields attached in the screenshot. I ran the tests on both open and closed incidents.

    Data transferred in pre-process script,The post process-script was not changed by me and is the same as in the documentation.

    The error message it receives looks as follows:

    I am very much counting on your help, I have no idea how to solve this at the moment.

    Regards 
    Lukasz Tynski



    ------------------------------
    Łukasz Tyński
    ------------------------------


  • 2.  RE: QRadar Enhanced Data Migration - QRadar Offense Summary

    Posted Thu March 02, 2023 02:27 AM

    Hi Łukasz,

    Enable debug in the app using one of the two documents depending on whether you are using an App Host or integrations server

    Reproduce and take a look at the logs to see what is being returned after the AQL is sent to QRadar.

    Have you installed Analyst Workflow on QRadar and is it functional?

    Have you configured the correct parameter values that are used to construct the AQL? These values are specific to your requirements.

    Is the function getting results from QRadar within 10 minutes or the configured time out of the function?

    The log with debug enabled should provide a lot of insight. Also, take a look at the action status and workflow status of the incident.



    ------------------------------
    BEN WILLIAMS
    ------------------------------



  • 3.  RE: QRadar Enhanced Data Migration - QRadar Offense Summary

    Posted Fri March 03, 2023 06:32 AM

    Hi Ben, 

    Thank you for your quick response. I took advantage of the documentation you provided and am now using this way of reading the logs. 
    At the moment we have a problem with the Analyst Workflow application on the Qradar side, and it looks like this is the problem.

    Thanks for help.



    ------------------------------
    Łukasz Tyński
    ------------------------------