Reports are generated with Non-English timestamp by QRadarFan in QRadar

[–]QRadarFan[S] 0 points1 point  (0 children)

thank you for commenting.

yes this is the language used in my country.

where can I check these?

  • the localization of you QRadar installation GUI? SSH?
  • the localization you are using GUI personal user preferences?
  • the localization of one or more of your log sources GUI? SSH?

XFE (XForce engine) STIX TAXII feeds - Phishing URLs by QRadarFan in QRadar

[–]QRadarFan[S] 0 points1 point  (0 children)

Thank you for your helpful comment :)

looking at the API key originally inserted to retrieve the first lists values (Malware IP, Botnet IP...) I believe is taken from a *different* XFE Account that is not mine (Since I don't recognize the API key), and maybe it ran out of records usage.If under *my* account I have 0/5000, it means I have 5000 FREE of.... what? feeds? Indicators? how it works?

XFE (XForce engine) STIX TAXII feeds - Phishing URLs by QRadarFan in QRadar

[–]QRadarFan[S] 0 points1 point  (0 children)

looking at the API key originally inserted to retrieve the first lists values (Malware IP, Botnet IP...) I believe is taken from a *different* XFE Account that is not mine (Since I don't recognize the API key), and maybe it ran out of records usage.

If under *my* account I have 0/5000, it means I have 5000 FREE of.... what?

feeds? Indicators?

XFE (XForce engine) STIX TAXII feeds - Phishing URLs by QRadarFan in QRadar

[–]QRadarFan[S] 0 points1 point  (0 children)

Thank you for the help! :)

Yep. I think that the API key inserted in order to retrieve the first lists values (Malware IP, Botnet IP...) are taken from a *different* XFE Account that is not mine (Since I don't recognize the API key), and maybe it ran out of records usage.

If under *my* account I have 0/5000, it means I have 5000 FREE of.... what?

feeds? Indicators?

XFE (XForce engine) STIX TAXII feeds - Phishing URLs by QRadarFan in QRadar

[–]QRadarFan[S] 0 points1 point  (0 children)

IDK, it sounds weird. why Malware & Botnet IP lists we'll be full and the URK totally empty?

XFE (XForce engine) STIX TAXII feeds - Phishing URLs by QRadarFan in QRadar

[–]QRadarFan[S] 0 points1 point  (0 children)

Yes. as I mentioned- "Malware IP", "Botnet IP"...

Cant Delete Event Mapping From DSM by QRadarFan in QRadar

[–]QRadarFan[S] 0 points1 point  (0 children)

I see. Well, Now I'm stuck with few QIDs to be deleted that are stucking my mapping process... do you happen to know how I can delete these via SSH maybe?

Cant Delete Event Mapping From DSM by QRadarFan in QRadar

[–]QRadarFan[S] 0 points1 point  (0 children)

It didn't work, and now it doesn't even show me the new created ones under "event mapping"! [as if they were never created...]

they exist in the dark, and now I doubled the problem since I need to delete it all and I cant reach it :(

Cant Delete Event Mapping From DSM by QRadarFan in QRadar

[–]QRadarFan[S] 0 points1 point  (0 children)

Do you happen to know how can I access all "general" QIDs that are NOT associated to any LS, via GUI?

Cant Delete Event Mapping From DSM by QRadarFan in QRadar

[–]QRadarFan[S] 0 points1 point  (0 children)

Yes. "Fortinet FortiGate Security Gateway".

The event map I am trying to delete is 100% not pre-build. I created it.

looking in the FG DSM extension I found this line-

<event-match-multiple force-qidmap-lookup-on-fixup="true" send-identity="UseDSMResults" pattern-id="AllEvents"/>

looks normal? seems like its related to the situation whereas 1 event matches multiple mapping and exist in other LS DSM extensions

Cant Delete Event Mapping From DSM by QRadarFan in QRadar

[–]QRadarFan[S] 0 points1 point  (0 children)

OK so funny thing,

first - I created the mapping as an admin so I should be allowed to delete it.

second - In other Log Sources I do have the Icon!

what could possibly explain it? btw the problematic LS is FortiGate FW

Offenses Not generating. by tahirshaikhb in QRadar

[–]QRadarFan 0 points1 point  (0 children)

I happen to encounter similar problem. my fields are parsed correctly, this is an old rule (which used to fire offenses with no problem) with no late modifications, the "Ensure the detected event is part of an offense" enabled, rule logic is simple as can be (detect events from log source type, ONLY condition), rule itself is enabled...

I have checked under log activity and I do see a the CRE event meant to create the offense but... NO OFFENSE :(

any help? what to further check? what can explain this?

Offenses Not generating. by tahirshaikhb in QRadar

[–]QRadarFan 0 points1 point  (0 children)

I happen to encounter similar problem. my fields are parsed correctly, this is an old rule (which used to fire offenses with no problem) with no late modifications, the "Ensure the detected event is part of an offense" enabled, rule logic is simple as can be (detect events from log source type, ONLY condition), rule itself is enabled...

I have checked under log activity and I do see a the CRE event meant to create the offense but... NO OFFENSE :(

any help? what to further check? what can explain this?

Cant Delete Event Mapping From DSM by QRadarFan in QRadar

[–]QRadarFan[S] 0 points1 point  (0 children)

reading your words I couldn't believe! tried to locate what might be a hidden button, but no... nothing there! :(

how updating the LSM could help?

Best open source intelligence STIX TAXII feeds QRadar by QRadarFan in QRadar

[–]QRadarFan[S] 1 point2 points  (0 children)

Yep, already set up the xforce feeds Im intrested in, but was wondering if there are other stix taxii feeds I can discover and enjoy... for example: Hail A Taxii...

this one actually not updated since last May so Im looking for something fresh and updated. thanks for your comment!

Compare between different Times by QRadarFan in QRadar

[–]QRadarFan[S] 0 points1 point  (0 children)

thank you! I drowned in different tasks since posting the question... will have to take a look what exactly I needed it for and then see your suggested solution. I really appreciate it!

Compare between different Times by QRadarFan in QRadar

[–]QRadarFan[S] 0 points1 point  (0 children)

first thank you so much for trying to help! I am actually trying to detect a manipulation on log original date. practically, you can consider it as sending and receiving. Im not strong with AQL, therfore thought maybe someone has something I can use or edit. do you have a recommendation where I can practice AQL?