IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Update the countries of public IP addresses on Qradar

    Posted Tue November 24, 2020 06:20 AM

    Hi Community,

    I am on version 7.33 Qradar, how will I be able to update the countries of public IP addresses on Qradar.

    Below is an example of @IP that arrive from Tunisia but not identified by Qradar or with the wrong country (197.244.175.25 Nigeria flag) :



    Help please!

    Best,

    ------------------------------
    Hichem AZAIEZ
    ------------------------------

    ------------------------------
    hichem azaiez
    ------------------------------


  • 2.  RE: Update the countries of public IP addresses on Qradar

    Posted Wed November 25, 2020 03:39 AM
    Hi Hichem

    Could you please check the documents if it has solution?
    https://www.ibm.com/support/pages/qradar-support-geodata-faq
    Regards

    ------------------------------
    Hasan Erhan AYDINOĞLU
    ------------------------------



  • 3.  RE: Update the countries of public IP addresses on Qradar

    Posted Wed November 25, 2020 08:30 AM

    Thanks for all very much.

     

    ------------------------------
    Hichem AZAIEZ
    ------------------------------


     






  • 4.  RE: Update the countries of public IP addresses on Qradar

    Posted Wed November 25, 2020 04:26 AM
    Hi Hichem.  You probably did already review the QRadar Geodata FAQ , nevertheless ? Few things pop to mind : Check under Admin > System Settings > Geographic Settings if you have the MaxMind account proprerly set and if the Country selection was set to Physical or Registered Location. In the lab (QRadar 7.4.1) I used the logrun.pl script with the spoofed IP address you stated and in thew Log activity UI I saw it as from Tunisia (my System settings > Country selection is set to Physical location).

    ------------------------------
    Dusan VIDOVIC
    ------------------------------



  • 5.  RE: Update the countries of public IP addresses on Qradar

    Posted Wed November 25, 2020 08:29 AM

    Thanks very much.

     

     

    ------------------------------
    Hichem AZAIEZ
    ------------------------------