IBM Support

QRadar: Anomaly Detection Engine creates unreadable events, for example "��@��� �H�"

Troubleshooting


Problem

Customers might notice that there are some events under an Anomaly Detection Engine log source that are not human readable. This issue occurs when the event generated from anomaly events is binary data, the user interface attempts to display the data, but instead shows question mark (��@���) characters.

Symptom

You can reproduce the issue with the following steps:
  1. Create an Anomaly Detection Rule.
  2. After the rule is triggered it creates at least two events, one of them with the event name given. 
  3. Select Display > Raw Events.
  4. The payload of the event displays ��� characters.
    image-20220216151624-4
  5. Double-click the event, the utf tab attempts to render the data, which is not human readable.
    image-20220303122615-2

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SS6E69","label":"IBM QRadar Network Insights"},"ARM Category":[{"code":"a8m0z000000cwtJAAQ","label":"QRadar Network Insights"}],"ARM Case Number":"TS007983538","Platform":[{"code":"PF016","label":"Linux"}],"Version":"All Versions"}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
08 March 2022

UID

ibm16557112