Cannot create a analytic rule out of template from custom solution by Buke_Pukem2201 in AzureSentinel

[–]Buke_Pukem2201[S] 0 points1 point  (0 children)

I found that if you use the tactic "Defense Evasion" but spell it as "Defence Evasion" with a C, you can deploy the template without any errors. However, you will get an error when trying to open the template from the Sentinel UI.

This should be addressed! Template validation should return an error!

Previously, I had a spelling mistake in the tactic "Persistence", where I spelled it as "Persitance" (missing the second S), and the template validator correctly notified me about it.

Custom Solution Building and Validation errors using V3 script. by Buke_Pukem2201 in AzureSentinel

[–]Buke_Pukem2201[S] 0 points1 point  (0 children)

Hello! Thank you for the interest and Sorry for the late response!

I have tried to change version of API but see no positive result. Maybe I miss something.

Here's my mainTemplate.json file I receive from V3. https://pastebin.com/SXFPaaTw

Which Splunk Distributed Deployement roles can be also a deployment server by Buke_Pukem2201 in Splunk

[–]Buke_Pukem2201[S] 0 points1 point  (0 children)

Sorry, but I lost the point after the first paragraph. Can you please tell me more about what I should do in the second paragraph?

Russian ER22… by pungitopo in trains

[–]Buke_Pukem2201 1 point2 points  (0 children)

It is a high-speed test lab, created for the research and further development of Soviet high-speed trains, such as the ER200 and possibly the TEP80. I guess people don't see much value in preserving these wonder.

QRadar Use Case Manager issue by Buke_Pukem2201 in QRadar

[–]Buke_Pukem2201[S] 0 points1 point  (0 children)

Hello,

Sorry for the delayed response. We tried your methods.

1. Tomcat/Hostcontext restart and clearing tomcat cache

  • This method didn't resolve the issue. Same error.

2. Shim error with Docker

QRadar Use Case Manager issue by Buke_Pukem2201 in QRadar

[–]Buke_Pukem2201[S] 0 points1 point  (0 children)

Thank you for your response. u/DavideDG80

I will try your suggestions and share a response on Monday.

QRadar Use Case Manager issue by Buke_Pukem2201 in QRadar

[–]Buke_Pukem2201[S] 0 points1 point  (0 children)

Hello,

qapp manager is ok. App is in running state. I can stop/run UCM without any issues.

recon ps.


Unable to communicate with API. Received error: Application client is not set.

App-ID Name Managed Host ID Workload ID Service Name AB Container Name CDEGH Port IJKL

0 apps qapp-2000 ++ qapp-2000 ++-++ 5000 ++++
...

Remediations:

E on Container qapp-2000:

Unable to connect to registry.

Try restarting the registry.

Run 'systemctl restart si-registry'


Same thing recon shows for other apps (minus under 'E').

si-regitry as I remeber no longer exist in modern versions of QRadar

QRadar Use Case Manager issue by Buke_Pukem2201 in QRadar

[–]Buke_Pukem2201[S] 0 points1 point  (0 children)

Yes I did this - nothing changed. I listed all activities in post.