IBM Support

QRadar Security Content Pack: IBM Guardium

Question & Answer


Question

A release note is now posted for the IBM Guardium Security Content Pack. This tech note outlines the changes and provides installation instructions for administrators.

Answer


Quick links  

What is in the IBM Guardium Security Content Pack?


The IBM Guardium extension adds one new custom event property for 'Database Name' to allow users to extract and search for the database name from IBM Guardium event payloads. This custom event property for IBM Guardium is enabled and optimized by default, which allows administrators to use the custom event property 'Database Name' in searches, reports, and rules.

New Custom Event Properties added by the IBM Guardium Security Content Pack
Description Regex for the custom event property
Database Name \|DBName=`?(.*?)`?\|


 

How do I install a security content pack?


To install a security content pack, an administrator must download the RPM from IBM Fix Central, then install the content pack on the Console appliance. The Console replicates the changes from the install of the content pack to all managed hosts in the deployment.

Procedure
  1. Download the IBM Guardium Content Pack from the IBM Fix Central website for your QRadar version:
  2. Using SSH, log in to your Console as the root user.
     
  3. Copy the security content pack to the /tmp directory on the QRadar Console. Note: If space in the /tmp directory is limited, copy the fix pack to another location that has sufficient space.
     
  4. To install the security content pack, type one the following command:
    • For QRadar 7.1, type: rpm -Uvh ContentPackage-CustomProperties-IBMGuardium-7.1-1409264316.x86_64.rpm
    • For QRadar 7.2, type: rpm -Uvh ContentPackage-CustomProperties-IBMGuardium-7.2-1409264316.x86_64.rpm
       
  5. Log in to the QRadar Console as an administrator.
     
  6. Click the Admin tab.

    Before you continue: Restarting the web server will restart the user interface and load the new custom event properties. This action will log out existing users, stop reports in progress, and halt event exports in process. It is recommended that administrators restart the user interface during a maintenance window for the appliance.
     
  7. Click Advanced > Restart Web Server.
     
  8. Click OK to restart the QRadar user interface.


    Results
    After the user interface restarts, the installation is complete. The administrator should review the IBM Security Privileged Identity Manager custom event properties to determine if any of the values need to be enabled, disabled, or optimized in the QRadar interface.


 

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000Gnd8AAC","label":"QRadar->Apps->Content Extensions"}],"ARM Case Number":"","Platform":[{"code":"PF016","label":"Linux"}],"Version":"All Versions","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
01 April 2020

UID

swg21971468