[Example-console-lab#/]/opt/qradar/bin/geodata_update.sh Result: 401 Unauthorized at /opt/qradar/bin/geoipupdate-pureperl.pl line 222, <$fh> line 37
Resolving The Problem
- Create a free MaxMind account: https://www.maxmind.com/en/geolite2/signup.
- After your account is created, an email is provided by MaxMind.
- Create a password for your account.
- After you assign an account password, use the credentials you created to sign in.
- Click My License Key.
- Click Generate new license key.
- Configure the following values:
- In the License key description, type: QRadar License Key.
- In the field, 'Will this key be used for GeoIP Update', select Yes.
- Select Generate a license key and config file for geoipupdate versions older than 3.1.1.
- Click Confirm.
- Record the Account/User ID and License Key information.
Important: If you exit the license key screen without recording the information, you must generate a new license key from Step 4.
- Log in to QRadar as an administrator.
- Click the Admin tab.
- Click the System Settings icon.
- Navigate to Geographic Settings.
- Update the User ID and License Key values from Step 5.
- Click Save.
- From the Admin tab, click Deploy Changes.
After the deploy completes, geographic data settings are updated for the QRadar deployment. Administrators can confirm their MaxMind geographic settings from the command line of the QRadar Console.
How to verify your geographic data license changes
Administrators can verify geographic data (geodata) updates from the QRadar command-line interface. After you update your System Settings to use your MaxMind User ID and License, you can attempt to run an update and verify whether any errors occur. To complete this procedure, you must have root access to QRadar.
- Use SSH to log in to your QRadar Console as the root user.
- To update geographic data, type:
- If successful, the administrator is returned to the command prompt with no errors displayed on screen.
- If unsuccessful, a 401 Unauthorized error is displayed. If you experience an error, confirm the credentials in the QRadar System Settings from Step 10, then click Save and Deploy Changes. Repeat the verification procedure or generate a new license key from the MaxMind website. If you continue to experience problems or believe the Deploy Changes does not complete successfully, open a case with QRadar Support.
31 March 2020