Pinned topic Q: a way of transporting BB and Rules between dev/QA and Production?
is there is way to transport Rules and Building Blocks between QA/Dev Qradar instances and Production? Would i want to do is to develop on non-production instances, do majority of research there and transport to production, followed by some limited testing and further tuning.
Any ideas on exporting/importing rules are welcome, scripting is not a problem.
-J.-------Posted BY Jakub Wartak
KKadow 270006NW4X1 Post
Re: Q: a way of transporting BB and Rules between dev/QA and Production?2013-10-22T17:30:23ZThis is the accepted answer. This is the accepted answer.
I noticed Import/Export was listed as a feature for the 7.1 release, but I don't see an easy option to actually do this in either 7.1 or 7.2?
Is there a reasonable mechanism for exporting and importing rules and/or building blocks between two QRadar systems both running v7.2p2?
Nikodim 2700016C6N32 Posts
Re: Q: a way of transporting BB and Rules between dev/QA and Production?2013-10-23T14:46:25ZThis is the accepted answer. This is the accepted answer.
- KKadow 270006NW4X
There's a CMT (Content Management Tool) available both in QRadar 7.1 and 7.2.
You can export and import basically all security content:
- Saved Searches
- Reference Sets
- Custom and Calculated Properties
- Custom Rules and Building Blocks
Check the attached document for details (from QR 7.1).
Aaron_Breen(IBM) 2700065Y0Q150 Posts
Re: Q: a way of transporting BB and Rules between dev/QA and Production?2013-10-24T17:35:44ZThis is the accepted answer. This is the accepted answer.
- Nikodim 2700016C6N
CMT is not a supported tool in 7.1 or current 7.2. It was a pre-release to the services group and a specific set of customers. We found issues which are scheduled for the next release. Please refrain for using this until you see it in the release notes and official documentation page