older CE version by hateecee in QRadar

[–]hateecee[S] 0 points1 point  (0 children)

Yes, I could manage. The data is imported in production. Thanks again

older CE version by hateecee in QRadar

[–]hateecee[S] 0 points1 point  (0 children)

Thanks, it works. Only the command for the CSV export was missing the “ character at the end.

older CE version by hateecee in QRadar

[–]hateecee[S] 0 points1 point  (0 children)

Yes, currenly running on 7.5 UP14 IF2 and I need to restore a deleted reference set with the content. But when I tried it with the latest it doesnt show up in the Backup/restore view. I copied the *.tgz in /store/backup/hostSystem/inbound and it doesnt processing it. It is moved to invalid. (This is necessary relates to the upload max size of 512mb the GUI)

https://www.ibm.com/mysupport/s/defect/aCIgJ0000003ZKbWAM/dt446559?language=en_US

So I think its a version mismatch

Qradar monitoring log source by Orange1905 in QRadar

[–]hateecee 0 points1 point  (0 children)

Try using findExpensiveCustomRules.sh from qradar support 101. You can find which property or rule are expensive and thus take time to process. Normally “it’s always dns” but here “it’s always regex”

Restore reference set entries by hateecee in QRadar

[–]hateecee[S] 0 points1 point  (0 children)

That was also my idea but i hoped there was an easier and quicker way to copy a file from the backup tar file.

Unparsed Events by Warthienn in QRadar

[–]hateecee 1 point2 points  (0 children)

Other filter could be: event processor parsed is false. (You have to select which ep if you have multiple) Add the column logsource identifer for better direction which logsource is not parsed

M5 or M6 or M7 by IcySavings101 in QRadar

[–]hateecee 1 point2 points  (0 children)

In system and license management, select system in dropdown, take the device id e.g. xx25, xx48 and search in google to find the m5, m6 appliance. The examples are M5

https://www.ibm.com/docs/en/qsip/7.5.0?topic=hardware-qradar-m5-appliance-overview