Applications 101 QRadar applications and application framework troubleshooting, common issues, technical help, and resources. IBM Security App Exchange Ask in our Forum

Important APARS and Notices

See all our technotes
Known Issues Notices
QRADAR PATCH IJ25734: QRADAR APP VERSION DOWNGRADES CAN OCCUR DURING A QRADAR PATCH

After installing a QRadar patch, any QRadar Apps already installed and that are included by default within the QRadar patch (e.g., Log Source Management App) should be verified for its version and updated.

QRADAR PATCH IJ23059: APPS CAN FAIL TO LOAD DUE TO CERTIFICATES NOT BEING RENEWED AS EXPECTED WHEN THE QRADARCA-MONITOR SERVICE HANGS

QRadar Apps can fail to load due to expired certificates not being renewed if the qradarca-monitor service is in a stuck state.

QRADAR PATCH IJ22709: QRADAR DEPLOYMENT INTELLIGENCE (QDI) APP ADVANCED HEALTH QUERY DISPLAYS BLANK GRAPHS FOR ENCRYPTED MANAGED HOSTS

The QRadar Deployment Intelligence (QDI) App displays blank graphs when attempting to perform an advanced health query on an encrypted Managed Host.

QRADAR PATCH IJ21567: RESET OF QRADAR CERTIFICATES CAN FAIL WHEN QRADARCA-MONITOR SERVICE IS RUNNING AT THE SAME TIME

The reset-qradar-ca.sh script can fail to reset all certificates properly if it encounters the same time as qradarca-monitor service is running.

QRADAR PATCH IJ21495: QRADAR APPS CAN GO OUT OF MEMORY DUE TO A RHEL KERNEL BUG WITH DENTRY SLAB CACHE

It has been identified that in some instances QRadar Apps can experience out of memory occurrences due to Red Hat Enterprise Linux (RHEL) kernel bug with dentry slab cache where kernel memory does not get freed as expected.

QRADAR PATCH IJ15968: MODIFIED SYSTEM RULES CANNOT BE DELETED DUE TO INFORMATION STORED BY THE DEPENDENCY CHECKER

It has been identified that System Rules (Building Blocks) that have been modified cannot be deleted due to information stored and used by the rule deletion dependency checker in QRadar.

Getting Started with Apps


Introduction to QRadar applications and common tasks, such as installation issues, backups, and case information to help administration.

QRadar applications FAQ


Connect the QRadar Assistant application to the X-Force App Exchange (07:54) Use the QRadar Assistant app to update applications (08:01)

How to use the Assistant application to manage applications How to monitor Deploy Changes progress.

Stopping, restarting, and uninstalling an app

Backup and restore applications How to open an app case with IBM Support Collecting logs for your application support case

Troubleshooting Help

App Framework Troubleshooting App Troubleshooting
QRADAR SERVICES QRadar: Services responsible for the applications and application framework functionality

What are the services responsible for the application framework functionality and how to check their status?

QRADAR APPLICATION QRadar: Verify whether an application is installed and the application framework docker container state

QRadar: How to verify the application framework docker images are installed and running?

DOCKER NETWORK Docker containers and network interfaces

A Docker network defines a communication trust zone where communication is unrestricted between containers in that network.

QRADAR TROUBLESHOOTING QRadar: Troubleshooting IPtables and applications (ERROR: iptables –wait -t nat -C DOCKER)

The application is installed and is displayed on the QRadar® dashboard, but the application does not appear to be working.

QRADAR CONFIGURATION QRadar: How to tune proxy configurations for app containers

Administrators who upgrade to QRadar versions 7.3.2 & above might experience issues where the global proxy configuration is pushed to all apps in the application framework.

Resources


Sites and resources recommended by the QRadar Support team.

Official documentation for all IBM Applications Checking app logs vs container logs How to check in postgres if the app is running UBA training videos on the IBM Security Learning Academy Self-serve application documentation