IBM Security QRadar

 View Only
  • 1.  Qradar Email fire too many offenses

    Posted Mon March 13, 2023 09:28 AM

    I assigned "Alert Email From Address" to certain email "qradar@exampledomain.com" to send emails from it.

    But this username "qradar" fires Too many authentication failed offenses "Multiple Authentication failed from same username to same destination"

    this email password expiration is 'never expire'.

    So how I eliminate these false-positive hits , Is there a way to troubleshoot?

    Should I reconfigure the email password , How?
    or exclude the username from the rule?,   or what else i could do?

    Thanks in advance



    ------------------------------
    Ahmed K. Awwad
    ------------------------------


  • 2.  RE: Qradar Email fire too many offenses
    Best Answer

    IBM Champion
    Posted Wed March 15, 2023 10:57 AM

    Ahmed,

    the from address you specifiy in system settings should match your Qradar host name . When you change it here make sure the hostname can be resolved correctly. No email password expiration involved here when sending to root@localhost. If you are using alert-config.xml to send emails to, al type of offenses will show up depending on email alert policy. Default policy will report "Multiple Authentication failed from same username to same destination" as usual. False Pos needs tuning. Pls look at https://www.youtube.com/watch?v=xhrYeD3Pxiw as a starting point. Includes way to troubleshoot. Easiest way to troubleshoot your policies is to use logrun.pl to import your exported log payload. Pls see Jose at https://www.youtube.com/watch?v=LHv6_JjhFU4

    Email password is ok. Dont change qradar password as long as you dont need. When you do use admin tab. Of course you can white list qradar user using a NOT condition. 



    ------------------------------
    [Karl] [Jaeger] [Business Partner]
    [QRadar Specialist]
    [pro4bizz]
    [Karlsruhe] [Germany]
    [4972190981722]
    ------------------------------



  • 3.  RE: Qradar Email fire too many offenses

    Posted Thu March 16, 2023 07:36 AM

    Great Thanks Mr. Karl Jaeger for your response .
    I am not sending to root@localhost but let me break it , you mean by "the from address you specify in system settings should match your Qradar host name" that my domain name like "entitydomain.com" is correct , so Yea I am sure and it's already sending Emails well.
    And only failed to Authenticate randomly , so I think I will go with excluding the username as you said.



    ------------------------------
    Ahmed K. Awwad
    ------------------------------