IBM QRadar SOAR

IBM QRadar SOAR

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  inbound emails missing occasionally

    Posted Wed April 20, 2022 04:27 PM
    There are inbound emails missing in my resilient (42.2) inbox from time to time... I have imap configured (test always successful) with outlook and I can see all emails on server with my simple python imap script easily.  These missing emails don't show up in resilient-email.log at all. The volume of emails is low, like one or two per hour so it is not performance issue.

    ------------------------------
    Irek Romaniuk
    ------------------------------


  • 2.  RE: inbound emails missing occasionally

    Posted Thu April 21, 2022 10:33 AM
    Hello!
      To be clear, do specific emails fail to be retrieved from the server, without any mention in the logs?
      How are you processing emails once they are retrieved? In theory if a script associates the message with an incident then the message will not appear on the inbox page. 
      There could also be a problem recorded in the client.log file, depending on what is actually happening.
    -P.J.

    ------------------------------
    Patrick (PJ) McKenna
    SOAR Development
    ------------------------------



  • 3.  RE: inbound emails missing occasionally

    Posted Thu April 21, 2022 02:27 PM
    Right, nothing in the resilient-email.log , any log... I don't expect them in the inbox.

    ------------------------------
    Irek Romaniuk
    ------------------------------



  • 4.  RE: inbound emails missing occasionally

    Posted Thu April 21, 2022 02:38 PM
    Edited by Jared Fagel Thu April 21, 2022 03:02 PM
    We've noticed this too (very occasional missing inbound emails). Its been too difficult to reproduce to be useful for IBM Support.

    ------------------------------
    Jared Fagel
    Cyber Security Analyst
    ALLETE Inc.
    ------------------------------



  • 5.  RE: inbound emails missing occasionally

    Posted Thu April 21, 2022 02:44 PM
    Did you use IMAP ? I have ticket opened since a week..

    ------------------------------
    Irek Romaniuk
    ------------------------------



  • 6.  RE: inbound emails missing occasionally

    Posted Thu April 21, 2022 03:02 PM
    We do not.

    ------------------------------
    Jared Fagel
    Cyber Security Analyst
    ALLETE Inc.
    ------------------------------



  • 7.  RE: inbound emails missing occasionally

    Posted Thu April 21, 2022 03:39 PM
    it has to be that resilient-email.jar having issues, bug probably

    ------------------------------
    Irek Romaniuk
    ------------------------------