QRadar

The IBM QRadar 7.6.0 family of products includes enhancements to operational efficiency and flow improvements. An update package includes new features, enhancements, and bug fixes to improve the performance and functions of QRadar. They are available for download from the IBM Support Fix Central.

Template

Description of the new feature, presented as "the problem that we have solved"

Business case for when customer might benefit from the new feature.

New information Learn more about...

New information Learn more about...

New information To learn more about <topic>, see the Name of guide.

QRadar 7.6.0

Attack Timeline
QRadar introduces the Attack Timeline to provide a chronological view of offense progression. The timeline displays key milestones, including the initial offense trigger, rule contributions, and when new users, hosts, or log sources are involved. Each milestone includes contextual details such as event names, IP addresses, hostnames, and contributing rules. Analysts can open a drill‑down panel to review more details without going away from the timeline. Progressive loading is used to support investigations with high event volumes. Rendering is optimized to maintain responsiveness during extended analysis sessions. The feature scales from individual analyst workstations to shared SOC displays. Administrators can configure availability and system‑level limits to manage performance. 
Multi‑value Custom Event Properties (CEP)  
QRadar supports extracting and storing multiple values for a single custom event property. The DSM editor can capture repeated matches and persist them as a list. Events that contain repeating fields retain all relevant values instead of a single parsed instance. The user interface indicates when a custom property contains multiple values. UI searches evaluate all values that are associated with the property. AQL queries also process all captured values consistently. Parsing and query performance are preserved through optimized handling. This update improves analysis of modern event formats with list‑based data.
Parsing order of a custom event property (API Control)  
QRadar adds API support for retrieving and modifying the execution order of parsing of custom event property. Administrators can use the API to standardize parsing order across environments. Changes that are made through the API are reflected in the DSM editor for visibility. Impact analysis identifies potential parsing conflicts before changes are applied. This capability supports automated configuration management workflows. Predictable parsing behavior is maintained when multiple expressions apply to the same event data. The update reduces inconsistencies in field extraction. Event classification accuracy is improved at scale. 
Bulk Asset Management APIs  
QRadar introduces APIs that support bulk creation and deletion of assets. With the Bulk Assets Management API, users can run multiple operations, such as creating and deleting assets, in a single request. These operations are processed asynchronously in the background, allowing users to track progress and view results through a status endpoint. The status endpoint provides detailed information for each operation, including any failure error messages, helping reduce manual effort and making asset management more efficient.
Red Hat NetworkManager adoption   
The transition to Red Hat NetworkManager provides QRadar with a modern, standardized infrastructure for managing network devices and configurations. This approach aligns with Red Hat’s roadmap for RHEL 9 and RHEL 10, and ensures long-term compatibility and support. NetworkManager introduces flexible management options through multiple interfaces, including CLI, API, and message bus, enabling deeper integration with QRadar deployment workflows.

By replacing older custom scripts with NetworkManager, QRadar simplifies network configuration and reduces complexity, minimizing the risk of errors during setup and maintenance. Administrators benefit from improved efficiency and consistency, making it simple to manage network settings across deployments. This update also provides the foundation for further enhancements in security and scalability, and delivers general stability and usability improvements for a more reliable experience. 

Editable Log and Network Activity filters  
Search filters in Log Activity and Network Activity are editable, simplifying workflows and improving efficiency. Filter input function is improved to support lists of values and configurable delimiters. The filter The Offense is remains excluded from editing.
Cloud High Availability (AWS) preparation
Preparation work for Cloud High Availability on AWS is completed. Red Hat NetworkManager migration is finalized for multi‑host deployments. Packaging supports both new AMI installations and upgrade scenarios. Signed RPMs are included for secure deployment. Health‑check documentation supports operational verification. Troubleshooting guidance is provided for common issues. Internal support workflows are aligned with the changes. This work establishes a foundation for AWS Cloud HA enablement.
DC-DR Health-Check Dashboard API for 24x7 Resilience Validation (Phase 1)
Available in QRadar 7.6.0, this API enables network connectivity checks between DC and DR environments and is invoked by the Data Synchronization app. Support is provided in the Data Synchronization app version 4.0.0. The DC-DR Health Dashboard provides a single-pane view of resilience posture with automated failover/failback validation checks, available on demand or on a schedule. It includes network connectivity, backup and storage, deployment topology, and system configuration checks to help reduce operational risk during site outage.
Improved search filtering capabilities   
The Managed Search Results page now includes a new text‑based filter, enabling administrators to efficiently filter search results across most search properties.
TLS 1.3 Decryption Capability (QNI)
QRadar Network Insights now supports controlled decryption of TLS 1.3 traffic when organizations use approved SSL proxies or key-based setups. This helps SOC teams see the full content of network traffic for better threat detection and investigation. The feature is designed with strict policy and audit controls to ensure that it is used only where allowed. Users can choose between basic metadata view or full decrypted inspection based on their security needs and compliance rules.
Performance improvements 
Search performance is improved up to 5 times for events and flows that use reference set filters. This improvement builds on the search performance enhancements that are introduced in QRadar 7.5.0 UP15.  

The maximum rate for CRE rule responses that add data to reference data structures is increased by 2 times.

Attention: In QRadar 7.5.0 UP15, high availability systems that host apps (either the Console or an App Host) use the shared VIP address for routing when applications communicate with the internet. This change might cause issues with internet communication in some environments.
  • If your third-party devices or software (VPN, firewall) use the HA host's physical IP addresses to allow internet communication from the QRadar host or apps, communication might fail after you upgrade to QRadar 7.5.0 UP15. This occurs when the devices are not configured to use the VIP.
  • The updates in QRadar 7.5.0 UP15 is by design. Configure your third-party devices to use the VIP for communication between QRadar apps and the internet. IBM QRadar Support does not support third-party software.