IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only

Reindex data after snapshot restore

  • 1.  Reindex data after snapshot restore

    Posted Tue August 22, 2023 08:49 AM

    Hi guys, I have a particular situation and I didn't found anything useful googling.

    On our on prem QRadar instance, we got a critical problem that forced us to perform a snapshot restore in a urgent manner.
    Due this, we counldn't perform a save of indexed data and so, after the restore, we have no logs in time period between snapshot image (20/07) and restoration date (03/08). Now this data could be required.
    About reindexing data, I found this: QRadar: Creating event and flow indexes after restoring data on a managed host appliance but, correct if I'm wrong, this works if data has been indexed and then deleted. In our scenario, due the snapshot restore, it's like data has never been indexed by QRadar, so this procedure is not fine.

    My question so is: is there a way to reinsert this data (that are still on data sources) from log sources to QRadar?



    ------------------------------
    Luca Sepe
    ------------------------------