IBM Support

QRadar: All log sources are not collecting events after an upgrade



The ECS service might not listening on port 514 or any other major ports after an upgrade.


You might find the following error message in the /var/log/qradar.log:

Error attempting to load
DemoQRADAR.example.NET:ecs-ec/EC/Q1Labs_SyslogRedirect Error :


This happens when the option "Auto Restart Service" in the Auto Update page is disabled. By design, Protocols are not being installed when this option is disabled.

Resolving The Problem

To Resolve this issue use this procedure.

  1. Log in to the QRadar User Interface.
  2. Open the Admin settings:
    1. In IBM Security QRadar V7.3.1, click the navigation menu , and then click Admin to open the Admin tab.
    2. In IBM Security QRadar V7.3.0 or earlier, click the Admin tab.
  3. Click AutoUpdates icon.
  4. Click Get New Updates > Install All Updates.
  5. Once this completes from the Admin page click Advanced > Restart Web Server.


To prevent the problem from reoccurring do the following.


  1. From the Admin tab, click AutoUpdates icon > Change Settings.
  2. Check the box to enable the Auto Restart Service > click Save.
  3. Changes do not need to be Deployed.




Results: Log Sources are now collecting events.


Where do you find more information?


[{"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Upgrade","Platform":[{"code":"PF016","label":"Linux"}],"Version":"Version Independent","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
31 August 2018