IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  QRadar Lab - Logs not received

    Posted Mon September 11, 2023 10:03 AM

    Hello,

    Please help me with my lab. 

    I Installed the newest QRadar CE on both VMware and Virtual Box.
    Both work fine and the console has no issues. 

    The second stage is to install Wincollect, I installed it with CLI like IBM Helps guide due to errors with the regular installation.
    After entering the IBM Console I noticed an error at the bottom "QRadar Error - Retrying Connect timed out"
    To confirm the network connectivity is ok I entered the "Agent Settings" and ran the network test.
    The network test failed both in UDP and TCP. 

    Side note: I can't ping my QRadar hosts from any of my Windows machines.
    However, I can ping my Windows machines from my QRadar hosts (I don't know if it's related).
    I cant see any logs in the log activity and I tried every solution out there, I spent a whole day troubleshooting.

    Screenshots are attached.

    May appreciate any help!



    ------------------------------
    cygnus lab
    ------------------------------


  • 2.  RE: QRadar Lab - Logs not received

    Posted Fri September 15, 2023 09:49 AM

    Hey mate, 

    I had dealt with the same issue! 

    There's a product licensing issue for QRadar 7.3.3 & 7.4.2. 

    Go through the below link and execute a command specified in the document! 

    https://www.ibm.com/support/pages/node/6395080

    YouTube Video Reference: 

    https://youtu.be/IwkEm772EZI?si=8waDJ-mO5QHNp67G

    I hope this will resolve the problem. 

    All the best, mate. 

    Cheers. 



    ------------------------------
    Vamshi Rayarao
    ------------------------------