Hello @Liam Mahoney , @Richard Giesige , @Jonathan Pechta , @Marie Berinyuy,
The ownership of the code of the IBM Security QRadar Event and Flow Exporter App has moved to IBM Technology Exper Labs - Security. Communication, inquiries and suport has moved to sel.apps@ibm.com.
The issue is known. If you are interested to work with us actively on fixing the issue, please let us know.
Jens-Uwe Fimmen for sel.apps@ibm.com
------------------------------
Jens-Uwe Fimmen
------------------------------
Original Message:
Sent: Mon August 21, 2023 03:23 PM
From: Richard Giesige
Subject: IBM Security QRadar Event and Flow Exporter App sending multiple emails for the same report
@Jonathan Pechta did you ever get an update on if this was ever going to be patched or fixed since it's a known issue?
------------------------------
Richard Giesige
Security Engineer
Oshkosh Corporation
Oshkosh
Original Message:
Sent: Fri April 28, 2023 12:03 PM
From: Jonathan Pechta
Subject: IBM Security QRadar Event and Flow Exporter App sending multiple emails for the same report
This is currently a known issue. I've reached out to the development team for more information, but this issue is known and will require an app update to resolve I believe. I'll respond when I know more, but be aware that this is not something that QRadar Support can assist with, so I've reached out to the Security Expert Labs team that owns the application for more information.
------------------------------
Jonathan Pechta
QRadar Support Content Lead
Support forums: ibm.biz/qradarforums
jonathan.pechta1@ibm.com
Original Message:
Sent: Thu April 27, 2023 11:11 AM
From: Marie Berinyuy
Subject: IBM Security QRadar Event and Flow Exporter App sending multiple emails for the same report
I recently installed the Event and Flow Exporter App on my Qradar 7.5.00 UP3 IF 2 environment.
It works fine and generates reports based on the defined schedule but I've noticed that each day we get one extra email of the scheduled report.
Looking at the app's logs I see multiple Dummy threads created for a single report.
Example: Query 6 created on April 17th 2024.
Notice in "Dummy threads.png" that progressively there is an extra Dummy thread each day after that.
Each thread results in a new email with the same results.
Looking in the UI however we only see 1 report daily "Results.png"
Is anyone experiencing this same thing? Any ideas on how to prevent multiple threads from being created?
------------------------------
Marie Berinyuy
------------------------------