IBM Support

Release of QRadar 7.2.7 Patch 2 (7.2.7.20160816201941)

Release Notes


Abstract

This release note describes the fixed issues and installation procedures for IBM Security QRadar 7.2.7 Patch 2 (7.2.7.20160816201941).

Content

About

QRadar 7.2.7 Patch 2 is a replacement update for QRadar 7.2.7 Patch 1, which was removed due to APAR IV87973. Not all users will experience the issue described in IV87973, however, QRadar 7.2.7 Patch 2 is being issued as a replacement download. This update also resolves an issue in Chrome introduced by Google in browser v52 and v53.


Prerequisites

If your deployment is installed with QRadar 7.2.4 (any patch level) or later, you can install fix pack 7.2.7-QRADAR-QRSIEM-20160816201941.

Note: The 7.2.7-QRADAR-QRSIEM-20160816201941 fix pack can upgrade QRadar 7.2.4 to 7.2.6 (any patch level) and above to the latest software version. However, this document does not cover all of the installation messages and requirements. For information on upgrading from QRadar 7.2.4 or later, see the QRadar Upgrade Guide.



Before you begin

Ensure that you take the following precautions:

  • Back up your data before you begin any software upgrade. For more information about backup and recovery, see the IBM Security QRadar Administration Guide.
  • To avoid access errors in your log file, close all open QRadar sessions.
  • The fix pack for QRadar cannot be installed on a managed host that is at a different software version from the Console. All appliances in the deployment must be at the same software revision to patch the entire deployment.
  • Verify that all changes are deployed on your appliances. The patch cannot install on appliances that have changes that are not deployed.



About this task

Fix packs are cumulative software updates to fix known software issues in your QRadar deployment. QRadar fix packs are installed by using an SFS file. The fix pack can update any appliance that is attached to the QRadar Console that is at the same software version as the Console.


    Procedure
    1. Download the fix pack 7.2.7-QRADAR-QRSIEM-20160816201941 from the IBM Fix Central website: http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Security%2BSystems&product=ibm/Other+software/IBM+Security+QRadar+SIEM&release=7.2.0&platform=Linux&function=fixId&fixids=7.2.7-QRADAR-QRSIEM-20160816201941&includeRequisites=1&includeSupersedes=0&downloadMethod=http&source=fc
    2. Using SSH, log in to your system as the root user.
    3. Copy the fix pack to the /tmp directory on the QRadar Console.

      Note: If space in the /tmp directory is limited, copy the fix pack to another location that has sufficient space.
    4. To create the /media/updates directory, type the following command: mkdir -p /media/updates
    5. Change to the directory where you copied the patch file. For example, cd /tmp
    6. To mount the patch file to the /media/updates directory, type the following command:
      mount -o loop -t squashfs 727_QRadar_patchupdate-7.2.7.20160816201941.sfs /media/updates
    7. To run the patch installer, type the following command: /media/updates/installer

      Note:
      The first time that you run the fix pack, there might be a delay before the fix pack installation menu is displayed.
    8. Using the patch installer, select all.
      • The all option updates the software on all appliances in the following order:

        1. Console
        2. Event Processors
        3. Event Collectors
        4. Flow Processors
        5. Flow Collectors
      • If you do not select the all option, you must select your Console appliance.

        As of QRadar 7.2.6 Patch 3 and later, administrators are only provided the option to update all or update the Console appliance as the managed hosts are not displayed in the installation menu. After the Console is patched, a list of managed hosts that can be updated is displayed in the installation menu. This change was made starting with QRadar 7.2.6 Patch 3 to ensure that the Console appliance is always updated before managed hosts to prevent upgrade issues.

        If administrators want to patch systems in series, they can update the Console first, then copy the patch to all other appliances and run the patch installer individually on each managed host. The Console must be patched before you can run the installer on managed hosts.

        If your Secure Shell (SSH) session is disconnected while the upgrade is in progress, the upgrade continues. When you reopen your SSH session and rerun the installer, the patch installation resumes.

    9. After the patch completes and you have exited the installer, type the following command: umount /media/updates
    10. Administrators and users should clear their browser cache before logging in to the Console.


      Results
      A summary of the fix pack installation advises you of any managed host that were not updated. If the fix pack fails to update a managed host, you can copy the fix pack to the host and run the installation locally.

      After all hosts are updated, administrators can send an email to their team to inform them that they will need to clear their browser cache before logging in to the QRadar SIEM interface.


Resolved issues


As QRadar 7.2.7 Patch 2 is a cumulative release, the release notes listed below include additional tables for issues resolved in previous 7.2.7 patch updates. Note: Some APAR links in the table below might take 24 hours to display properly after a software release.


Issues resolved in 7.2.7 Patch 2
Product Number Description
QRADAR IV87973AFTER PATCHING TO 7.2.7 PATCH 1, THE /VAR/LOG/ PARTITION CAN RUN OUT OF FREE SPACE, CAUSING QRADAR SERVICES TO SHUTDOWN
QRADARIV87515"TYPEERROR: CANNOT READ PROPERTY '1' OF UNDEFINED" WHEN ACCESSING RULES PAGE USING CHROME BROWSER VERSION 53

Issues resolved in 7.2.7 Patch 1
Product Number Description
QRADARIV71970NO ACCUMULATED DATA FOR 'SOURCE NETWORK GROUP' COLUMN
QRADARIV74147REPORTS RUN ON ADVANCED SEARCHES CONTAINING THE 'HAVING' CLAUSE PRODUCE DUPLICATE COLUMNS
QRADARIV76224ERROR 'PATCH ABORTED' WHEN PATCHING QRADAR MANAGED HOSTS FROM THE CONSOLE USING THE PATCH ALL OPTION
QRADARIV77615QFLOW PROCESS ON QRADAR 1310 APPLIANCES CAN SOMETIMES STOP WORKING CAUSING NO FLOWS TO BE RECEIVED
QRADARIV80159REPORTS USING AN ADVANCED SEARCH WITH MULTIPLE 'ORDER BY' COLUMNS CAN FAIL TO BE GENERATED SUCCESSFULLY
QRADARIV80662REPORTS CONTAINING TABLES BASED ON SOME ADVANCED SEARCHES CAN CONTAIN EXTRA COLUMNS AND/OR BE MISSING COLUMNS
QRADARIV81818CHANGES MADE TO THE GLOBAL SYSTEM NOTIFICATION, SYSTEM LOAD, VALUES ARE NOT RECOGNIZED BY QRADAR
QRADARIV82018DEPLOY FUNCTION FAILS AFTER REMOVING ENCRYPTION USING SYSTEM AND LICENSE MANAGEMENT OPTIONS
QRADARIV82557'ERROR OCCURED WHILE SEARCHING FOR DEPENDENTS' MESSAGE WHEN ATTEMPTING TO DELETE A RULE FROM THE USER INTERFACE
QRADARIV82813SOME TIME SERIES DASHBOARD GRAPHS ONLY SHOW LAST SIX MINUTES OF EVENTS
QRADARIV82814OFFENSE SEARCH BY 'DESTINATION IP' CAN CAUSE A TOMCAT TXSENTRY MAKING THE USER INTERFACE TEMPORARILY INACCESSIBLE
QRADAR VULN. MANAGERIV83527QRADAR VULNERABILITY MANAGER SCANS CAN FAIL WHEN THERE ARE TOO MANY IP EXCLUSIONS DEFINED
QRADAR VULN. MANAGERIV83534QRADAR VULNERABILITY MANAGER PROCESSOR FAILS TO START WHEN A SCANNER INSTANCE NAME IS TOO LONG
QRADARIV83692UNABLE TO DELETE CUSTOM EVENT PROPERTIES WHEN THEY ARE USED WITH MULTIPLE LOG SOURCE TYPES AND SEARCHES
QRADARIV83769NAVIGATING TO THE 'MY ASSIGNED VULNERABILITIES' SCREEN CAN HANG AND THE USER INTERFACE CAN BECOME INACCESSIBLE
QRADARIV83969UNABLE TO CREATE NEW NETFLOW FLOW SOURCE FORWARDS OR EDIT ANY THAT ARE ALREADY CREATED
QRADARIV84004USING A LOG SOURCE EXTENSION (LSX) SET TO 'PARSING OVERRIDE' ON A STANDARD DSM CAN CHANGE THE EVENT SEVERITY LEVEL
QRADAR VULN. MANAGERIV84031RUNNING QRADAR VULNERABILITY MANAGER SCANS DISTRIBUTED ACROSS MULTIPLE SCANNER INSTANCES WITH CENTRALISED CREDENTIALS MAY FAIL
QRADARIV84058MANAGE VULNERABILITY DEPLOYMENT SCREEN 'SAVE' BUTTON IS NOT USABLE IN SOME CIRCUMSTANCES
QRADARIV84603DEPLOYMENT_INFO.SH AND GET_LOGS.SH CAN FAIL TO COMPLETE IN A QRADAR ENVIRONMENT THAT CONTAINS NAT'D HOSTS
QRADARIV84678QRADAR USER INTERFACE SCREEN MOVES ERRATICALLY WHEN USING SPECIFIC CHARACTERS IN THE OFFENSE CLOSING 'NOTE' SECTION
QRADARIV85031EVENT COUNT CONTIBUTING TO AN OFFENSE DOES NOT MATCH THE NUMBER OF EVENTS WHEN DISPLAYED IN LOG ACTIVITY
QRADARIV85157COMPLEX ADVANCED SEARCHES CAN CAUSE ACCUMULATOR_ROLLUP TO RUN OUT OF MEMORY
QRADARIV85207'COULD NOT DESERIALIZE QUERY HANDLE...-ASYNCHRONOUS' NULLPOINTEREXCEPTIONS REPETITIVELY APPEARING IN QRADAR
QRADAR VULN. MANAGERIV85252THE MANAGE VULNERABILITY PAGE IN THE QRADAR USER INTERFACE CAN SOMETIMES TAKE A LONGER THAN EXPECTED TIME TO LOAD
QRADAR VULN. MANAGERIV85261AN 'APPLICATION ERROR' CAN BE SOMETIMES BE GENERATED WHEN CLICKING A HYPERLINK ON THE SCAN RESULTS PAGE
QRADARIV85370QRADAR PATCHES CAN SOMETIMES TAKE AN UNEXPECTEDLY LONG TIME TO COMPLETE
QRADARIV85415'APPLICATION ERROR' ON THE CONFIGURATION MONITOR SCREEN WHEN ATTEMPTING TO VIEW A DEVICE SUMMARY
QRADARIV85447REPORTS AND DASHBOARDS BASED ON SOME ADVANCED (AQL) SEARCHES MIGHT NOT WORK AS EXPECTED
QRADAR VULN. MANAGERIV85449THE QRADAR VULNERABILITY MANAGER 'SCAN RESULTS' SCREEN CAN TAKE A LONGER THAN EXPECTED TIME TO LOAD/POPULATE
QRADARIV85599APPLICATION ERROR CAN SOMETIMES OCCUR WHEN ATTEMPTING TO CLOSE AN OFFENSE CAUSING A BLANK USER INTERFACE BROWSER WINDOW
QRADAR VULN. MANAGERIV85635'AN ERROR OCCURRED - UNABLE TO RETRIEVE SCAN RESULTS' ERROR DIALOG CAN SOMETIMES APPEAR WHEN OPENING SCAN RESULTS
QRADAR VULN. MANAGERIV85757QRADAR VULNERABILITY MANAGER SCHEDULED SCANS CAN SOMETIMES FAIL TO START
QRADAR RISK MANAGERIV85870UNABLE TO SEE ROUTE TO INTERNET IN TOPOLOGY WHEN PERFORMING A PATH SEARCH WHEN ROUTE IS THROUGH AN UNCLASSIFIED ISP ROUTER
QRADARIV86402THE VALUES ENTERED FOR REFERENCE SET DATA 'TIME TO LIVE' DAYS AND HOURS ARE SWAPPED AFTER CLICKING THE SUBMIT BUTTON
QRADARIV86686REPORTS BASED ON AN ADVANCED SEARCH (AQL) CAN SOMETIMES CAUSE REPORTING_EXECUTOR TO OUT OF MEMORY
QRADARSECURITY BULLETINIBM JAVA AS USED IN IBM QRADAR SIEM IS VULNERABLE TO INFORMATION DISCLOSURE. (CVE-2016-3426)
QRADARSECURITY BULLETINOPENSSL AS USED IN IBM QRADAR SIEM IS VULNERABLE TO MULTIPLE CVES

Issues resolved in 7.2.7
Product Number Description
QRADARIV50320WINCOLLECT AGENTS CONTAIN A DEFAULT EVENT THROTTLE THAT MIGHT NOT BE SUFFICIENT FOR HIGH EPS WINDOWS SYSTEMS
QRADARIV67458RULES THAT COMPARE A NUMERICALLY FORMATTED CUSTOM PROPERTY TO A NUMERICAL REFERENCE SET FAIL TO MATCH
QRADARIV72794THE QRADAR/STORE/TRANSIENT PARTITION CAN EXCEED 95% DISK SPACE USAGE CAUSING SERVICES TO STOP
QRADARIV73253QRADAR UNABLE TO ADD REFERENCE TABLE ELEMENTS WHEN USING PORT, IP, OR NUMERIC REFERENCE TABLES
QRADARIV76726GEOGRAPHIC COUNTRY/REGION DATA POPULATED INTO REFERENCE TABLES IS NOT USED CONSISTENTLY WHEN TESTING AGAINST OTHER RULES
QRADARIV78329UNABLE TO PERFORM RULE OR ADVANCED QUERY COMPARISONS USING 'DATE' TYPE REFERENCE DATA
QRADARIV78720OFFENSES CAN SOMETIMES STOP GENERATING OR UPDATING IN CERTAIN 'FLOW SOURCE STOPPED SENDING FLOWS' SCENARIOS
QRADARIV79198SYSTEM NOTIFICATIONS RELATED TO 'BERKELEY DB LIBRARY' CAN SOMETIMES BE GENERATED WITHIN QRADAR
QRADARIV79686NO SYSTEM HEALTH DATA IS DISPLAYED AFTER PERFORMING A QRADAR CONFIGURATION RESTORE
QRADARIV79698NON-ADMIN USERS ASSIGNED TO A DOMAIN ARE UNABLE TO SWITCH REPORT GROUPS
QRADARIV79930CREATING AN ASSET MANUALLY CAN TAKE A LONGER THAN EXPECTED AMOUNT OF TIME AND/OR APPEARS TO HANG INDEFINITELY
QRADAR VULN MANAGERIV81997AN ARIEL_PROXY_SERVER 'OUT OF MEMORY' CAN SOMETIMES OCCUR DURING EVENT AND/OR FLOW SEARCHES
QRADARIV82160CRE FAILED TO READ RULES MESSAGES IN QRADAR LOGGING AFTER PERFORMING A CONTENT MANAGEMENT TOOL IMPORT
QRADARIV83455DATA NODE REBALANCING PROCESS CAN SOMETIMES FAIL AND RESTART TAKING A LONGER THAN EXPECTED TIME TO REBALANCE
QRADARIV83535REPORT ON TOP OFFENSES THAT ARE BASED ON SAVED SEARCHES CONTAINING DOMAIN FILTERS DO NOT WORK AS EXPECTED
QRADARIV83748AN ERROR OCCURRED POSITIONING THE RESULT SET RETURNED FROM THE SERVER TO ROW 1...ERROR MESSAGE DISPLAYED IN SEARCH RESULTS
QRADARIV84025UNABLE TO DELETE RULES THAT ARE ADDED TO THE GROUP 'ANOMALY'
QRADARIV84056ADVANCED SEARCHES (AQL) THAT CONTAIN 'LOG SOURCE GROUP' FILTER OR COLUMN CAN APPEAR TO HANG
QRADARIV84062QRADAR USER INTERFACE ACTION BAR IS MISSING FROM MULTIPLE UI SCREENS
QRADARIV84390ERROR POP-UP OR BLANK WINDOW CAN OCCUR WHEN USING CHROME OR INTERNET EXPLORER BROWSER IN SPECIFIC FILTER SEARCH INSTANCES
QRADARIV81461LARGE NUMBER OF SIEM-AUDIT-2 SYSTEM GENERATED EVENTS WITHIN QRADAR
QRADARIV84511UNABLE TO REMOVE THE 'OPTIMIZE PARSING FOR RULES, REPORTS AND SEARCHES' FLAG ON CUSTOM EVENT/FLOW PROPERTIES
QRADARIV84682QRADAR VIS COMPONENT DOES NOT GET RE-ADDED TO QFLOW APPLIANCE WHEN A QFLOW IS REMOVED AND RE-ADDED TO A DEPLOYMENT
QRADARIV84689OFFLINE FORWARDING FROM DATA NODES DOES NOT WORK
QRADARIV84733QRADAR CAN FAIL TO PARSE EVENTS THAT HAVE UNRESOLVED DNS NAMES
QRADARIV85210INVALID BACKUP ARCHIVE MESSAGE WHEN ATTEMPTING TO UPLOAD A BACKUP FILE FROM WITHIN THE QRADAR USER INTERFACE







---------
Where do you find more information?


[{"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Documentation","Platform":[{"code":"PF016","label":"Linux"}],"Version":"7.2","Edition":"All Editions","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
10 May 2019

UID

swg27048566