IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  How to remove unreachable managed hosts with "unknown" status on QRadar SIEM

    Posted Sat December 31, 2022 08:07 AM
    Edited by Philip Ng Sat December 31, 2022 08:10 AM
    Hi guys,

    I have lately faced a problem where I want to remove an unreachable managed host with "unknown" status. Did tons of Googling but none of the solutions worked for me. It does not seem to be an easy task after all but shouldn't it be other way around? Imagine one of the managed hosts suddenly collapsed and you need to remove it on the console site...?

    Pardon me if there is actually an easy way out that I overlooked. Thank you in advance!

    Best Regards,
    Phil


  • 2.  RE: How to remove unreachable managed hosts with "unknown" status on QRadar SIEM

    Posted Mon January 02, 2023 11:50 AM
    Hi Phil,

    If in doubt, I would open a support ticket..

    Regards,
    Ralph

    ------------------------------
    Ralph Belfiore
    SIEM Expert
    pro4bizz GmbH
    Karlsruhe
    +4972190981727
    ------------------------------



  • 3.  RE: How to remove unreachable managed hosts with "unknown" status on QRadar SIEM

    Posted Wed January 04, 2023 09:09 AM
    Hi Ralph,

    Thanks for the quick response. I am just wondering how the managed host could be removed on the console site in a way that when web GUI does not work. I know altering the database would potentially fix it if I could pinpoint which components to remove and which not to, as I would like to rebuild and add a new host back to the console to replace the broken managed host and hopefully console could recognize and resume all the old settings. 

    Best Regards,
    Philip

    ------------------------------
    Philip Ng
    ------------------------------



  • 4.  RE: How to remove unreachable managed hosts with "unknown" status on QRadar SIEM

    Posted Tue January 03, 2023 01:19 AM
    Well, I am thinking about if the box is permanently unreachable? Is it decommissioned?  If not, a better way is to bring back the system online and then remove it from the deployment using UI.

    You can always open up a support ticket to get the help but above would be a better approach.

    Thank you.

    ------------------------------
    Prabir Meher
    ------------------------------



  • 5.  RE: How to remove unreachable managed hosts with "unknown" status on QRadar SIEM

    Posted Wed January 04, 2023 09:13 AM
    Hi Prabir,

    Thanks for your advice. I would like to proceed it the standard way if circumstances allow. Just wondering what I could do when the managed host is "dead" with its an unknown status. But yeah, maybe a direct support from the IBM team is the only way out... 

    Best Regards,
    Philip

    ------------------------------
    Philip Ng
    ------------------------------



  • 6.  RE: How to remove unreachable managed hosts with "unknown" status on QRadar SIEM

    Posted Thu January 05, 2023 01:40 PM
    You should be able to remove it from the deployment even if it is offline.

    ------------------------------
    Scott Searls
    ------------------------------



  • 7.  RE: How to remove unreachable managed hosts with "unknown" status on QRadar SIEM

    Posted Thu January 05, 2023 04:49 PM
    • What sort of Managed Host?
    • What version of QRadar?
    • Is HA involved?
    In most cases you should just be able to select "Remove Host" from the "Deployment Actions" after selecting the host in the System View of "System and License Management" - even if the host is unreachable.

    ------------------------------
    Paul Ford-Hutchinson
    ------------------------------