IBM Support

QRadar: Dynamic System Analysis (DSA) report

Question & Answer


Question

How do you run a Dynamic System Analysis (DSA) report for QRadar hardware issues?

Answer

Administrators who experience hardware issues on xSeries appliances should run the DSA utility and submit a report with the hardware support request.

Note: This answer provides two set of instructions, one for running the DSA utility for a hardware issue for when the xSeriers does boot up and another for when it does not boot up. See the instruction set that applies to your situation.

Instructions on running the DSA utility:
  1. Using SSH, log in to the remote QRadar appliance that is experiencing the hardware error.
    Note: You must first SSH to the Console, then open another SSH session to a managed host in the deployment.
  2. To change directory to the support folder, type:
    cd /opt/qradar/support
  3. To verify the permissions on the DSA utility, type: 
    ls -l ibm_utl_dsa*
    If permissions are "rw-r-r-", then you must change the permissions to be able to run the DSA utility.
  4. To change permissions, type: 
    chmod 755 ibm_utl_dsa_dsyta0r-9.61_portable_rhel6_x86-64.bin
    Note: For steps 4 and 5, the specific version will change over time, as the DSA utility is updated. Use the appropriate filename based on the output from step 3.
  5. To run a DSA report for your appliance, type: 
    ./ibm_utl_dsa_dsytd1o-9.61_portable_rhel6_x86-64.bin
  6. The DSA utility creates a .gz file in /var/log/IBM_Support with the machine type, serial number, and date.xml.gz.
    Example: /var/log/IBM_Support/7944AC1_KQ97NYC_20190302-163515.xml.gz
  7. Using WinSCP or other file transfer tool copy this file from the remote host and attach it to your support request for your hardware issue.

Instructions for running DSA utility on systems that do not boot:

Note: If your system will not boot, follow the instructions for the Preboot Edition of the DSA utility. Instructions are available here:
https://publib.boulder.ibm.com/infocenter/toolsctr/v1r0/index.jsp?topic=%2Fdsa%2Fdsa_c_technical_overview.html .

Administrators who experience hardware issues on xSeries appliances should run the DSA utility and submit a report with the hardware support request. The procedure below outlines how an administrator can collect a hardware report for an appliance that does not boot properly. This hardware report is required and must be submitted with the service request. This procedure can be followed for appliances that are suspended or frozen due to a hardware or software issue.
 
  1. Restart the QRadar Appliance.
  2. Select F2 to enter diagnostics.
  3. Hit ESC to stop memory test if it starts.
  4. After a menu appears, arrow over to Quit, then select Quit to DSA.
  5. Choose command line option: CMD.
  6. Insert a Fat 32 formatted USB flash drive. The output file is typically under 1MB.
  7. Choose to collect DSA with no other options needed. Choose NO when prompted to run DSA diagnostics.
  8. After two passes complete, exit back to the previous menu.
  9. Choose the option copy to local media.
  10. If USB flash drive is not seen, reseat, and try again. If the USB flash drive is still not seen, try a different USB device.
Note: The DSA can sometimes take a long time to start and run, which might appear to administrators that the DSA program is not functioning. However, do not interrupt this process as it can take up to 5 minutes between steps to collect the information and complete the report before writing this to the USB flash drive.

After the data is collected on the appliance, the files are saved to the USB flash device. The process of writing the files to the USB drive only takes a few seconds.

[{"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"Component":"Hardware","Platform":[{"code":"PF016","label":"Linux"}],"Version":"7.2;7.3","Edition":"","Line of Business":{"code":"LOB77","label":"Automation Platform"}}]

Document Information

Modified date:
18 June 2026

UID

swg21990898