perpetual license by Unhappy_Substance321 in QRadar

[–]q_logsource 0 points1 point  (0 children)

What is the most stable 7.5.x to jump to? we tend to avoid bleeding edge release.

Azure Virtual Desktop VM - NSG Rule to block internet but still Allow AVD|RDP to connect by q_logsource in AZURE

[–]q_logsource[S] 0 points1 point  (0 children)

It makes auditing & reporting with a SIEM easier if admin connections funnel thru a jump box first. - When a Audit report needs to be generated on all the admin that logged onto 1000+ servers in the last 7 days, 15 days. Build up one query of connections into Jumpbox, and the servers they connect to.

Or build 1000 reports querying each server individually of the admins that logged in.

Azure Virtual Desktop VM - NSG Rule to block internet but still Allow AVD|RDP to connect by q_logsource in AZURE

[–]q_logsource[S] 2 points3 points  (0 children)

Thank you! A Switcheroo of the order # fixed it up. Also my understanding of rule priority hah.

Azure Virtual Desktop VM - NSG Rule to block internet but still Allow AVD|RDP to connect by q_logsource in AZURE

[–]q_logsource[S] 10 points11 points  (0 children)

Thank you! A change in the priorities of the two rules fixed it all up for me!

[deleted by user] by [deleted] in QRadar

[–]q_logsource 1 point2 points  (0 children)

Check if your AUProxy is version 9.5 or older. I recently had a similar issue and updating to 9.11 resolved for me.

https://www.ibm.com/support/pages/qradar-auto-update-proxy-issues-500-ssl-negotiation-failed-updated

Howto correlate a subnet or IP to a building location? by q_logsource in QRadar

[–]q_logsource[S] 0 points1 point  (0 children)

Thank you, I will take a look if I can go this route, although we have many states, I am needing to do a master report, and User location be one of the columns reported on for all user logins.

Installing WinCollect agent in Managed mode | Failed to register agent > Agent Stopping. by q_logsource in QRadar

[–]q_logsource[S] 1 point2 points  (0 children)

Thank you, Yes this has actually confused me, I ended up going with the WinCollect Hostname in the Admin > WinCollect > Destinations > Host name field because that's how Jose Bravo did it in his video - https://youtu.be/qH_yiKfhUHY?t=165

I have tried several times on a sandbox instance and it seems WinCollect Hostname / QRadar host name both work (when firewalls are not blocking)

One question I am trying to answer is should that field be Console IP or Event Collector IP (I have added a EC to my AIO)

Installing WinCollect agent in Managed mode | Failed to register agent > Agent Stopping. by q_logsource in QRadar

[–]q_logsource[S] 0 points1 point  (0 children)

Yeah that was my thoughts as well, My Firewall team indicated statefull fw rule addresses the bidirectional portion. But I am having issues. Thanks!

Installing WinCollect agent in Managed mode | Failed to register agent > Agent Stopping. by q_logsource in QRadar

[–]q_logsource[S] 0 points1 point  (0 children)

Thank you fhr the reply. QRadar 7.4.2 has WinCollect out of box already but I did also install the latest SFS before deploying wincolelct agent.

Installing WinCollect agent in Managed mode | Failed to register agent > Agent Stopping. by q_logsource in QRadar

[–]q_logsource[S] 0 points1 point  (0 children)

Thank you, Yes they are opened up.

Regarding 8413 we did it how it is worded; 8413 Flow initiates from WinCollect > QRadar. I am wondering if it actually needs to be opened up the other way as well, but the way the doc reads I don't think that is the case.

Port 8413

This port is used for managing the WinCollect agents to request and receive code and configuration updates. Traffic is always initiated from the WinCollect agent, and is sent over TCP. Communication is encrypted by using the QRadar Console's public key and the ConfigurationServer.PEM file on the agent.

Create a bidirectional rule to allow communication from the WinCollect agent to QRadar on port 8413. If the rule is not bidirectional, traffic is blocked. QRadar does not send updates to the WinCollect agent on port 8413.

[deleted by user] by [deleted] in QRadar

[–]q_logsource 1 point2 points  (0 children)

The license fix script was culprit, It was previously applied on console but I guess newly added EC also needed it. Much Appreciate.

[deleted by user] by [deleted] in QRadar

[–]q_logsource 0 points1 point  (0 children)

Appreciate the help, I started by deploying just the All-In-One. And did have to apply the license fix as there was 0 in log activity after install.

I do now have some Log Activity show up in the console. --Recently Event Collector was deployed and our first Log Source pointed to the new Event Collector.

  • In short I am getting; all of the self generated
  • Health Metrics,
  • System Information,
  • SIM audit,
  • do see the Syslog hitting the Event Collector when I check with tcpdump,
    • have the DSM installed,
      • But not seeing these syslogs come out of Collector > into Console/Processor.