IBM Security QRadar

 View Only
  • 1.  Use Case Manager Export not working as expected?

    Posted Wed May 29, 2024 09:52 AM

    Hi all again,

    on a certain dev. environment the manager doesn't seem to be producing the desired effect - although the GUI shows that the export procedure has been started, no .zip / contents file can be found.

    At the same time the qradar.log is exhibiting the following errors:

    qradar.log:May 29 15:10:05 IPv6_COMES_HERE [accumulator_rollup.accumulator_rollup] [main] com.q1labs.frameworks.naming.FrameworksNaming: [INFO] [NOT:0000006000][HOST_IP_COMES_HERE/- -] [-/- -]com.ibm.si.content_management.types.ContentVersion.NAME MUST be public, static and not final for naming to help with setting of NAME
    qradar.log:May 29 15:14:16 IPv6_COMES_HERE [tomcat.tomcat] [USER_NAME_COMES_HERE]    at com.ibm.si.cmt.types.operation.ContentManagerExport.executeBulkOperations(ContentManagerExport.java:164)
    qradar.log:May 29 15:14:16 IPv6_COMES_HERE [tomcat.tomcat] [USER_NAME_COMES_HERE]    at com.ibm.si.cmt.types.operation.ContentManagerExport.doOperation(ContentManagerExport.java:65)
    qradar.log:May 29 15:14:16 IPv6_COMES_HERE [tomcat.tomcat] [USER_NAME_COMES_HERE]    at com.ibm.si.cmt.types.operation.ContentManagerOperation.operate(ContentManagerOperation.java:64)
    qradar.log:May 29 15:14:16 IPv6_COMES_HERE [tomcat.tomcat] [USER_NAME_COMES_HERE]    at com.ibm.si.cmt.ContentManager.operate(ContentManager.java:62)

    Has anyone encountered such an issue?

    Regarding the bolded part, could it be that the message is due to the fact that not all manifest.txt fields were populated (only the ones marked with * were)?

    Many thanks in advance,

    kind regards



    ------------------------------
    Vedran Zulin
    ------------------------------


  • 2.  RE: Use Case Manager Export not working as expected?

    Posted Thu May 30, 2024 06:27 AM

    Hi Vedran,

    Those logs appear to be from the accumulator process.  I would suggest you open a support case for this as a full set of logs for analysis would be required.

    Thanks



    ------------------------------
    John Dawson
    Qradar Support Architect
    IBM
    ------------------------------



  • 3.  RE: Use Case Manager Export not working as expected?

    Posted Fri May 31, 2024 09:00 AM

    Hi John,

    thanks for the reply!

    I think that I may have found what might be causing the behavior:
    "Extension management export tasks don't work in QRadar 7.4.3 FP7 and 7.5.0 UP3+.

    When you export multiple or single rules in a zip file, the export gets stuck, and never remains in a 'processing' state."
    Known issues - IBM Documentation

    Of course, will update the topic should any possible solution or important news come across...

    Thanks again,

    have a nice weekend,

    kind regards



    ------------------------------
    Vedran Zulin
    ------------------------------