IBM Support

QRadar: Local IP addresses recognized as Remote by Rule test due to Network Hierarchy configuration

Troubleshooting


Problem

IP addresses that are categorized as local in Log Activity are recognized as remote by a rule causing false positives.

Symptom

In the following example, the admin wants to identify events with some QID or characteristics, but only when the source IP address is remote.

So, the following rule is created with these tests: 
  • when the event QID is one of the following (3503982) IP ip WebVPN session started.
  • when the source is Remote
image-20221024224915-1
The Network Hierarchy is defined as follows. The IP 10.10.10.5 has an entry, so it is a local IP: 
image-20221024225140-2
Although the IP is defined as local in the Network Hierarchy, the rule detects this IP as a remote IP address generating false positives offenses:
image-20221024225355-3

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSV4BL","label":"IBM QRadar"},"ARM Category":[{"code":"a8m0z000000cwtrAAA","label":"Rules"}],"ARM Case Number":"TS010177353","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"},{"Product":{"code":"SSTZMA","label":"QRadar Appliance Hardware"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Component":" ","Platform":[{"code":"","label":""}],"Version":"","Edition":"","Line of Business":{"code":"LOB77","label":"Automation Platform"}}]

Log InLog in to view more of this document

This document has the abstract of a technical article that is available to authorized users once you have logged on. Please use Log in button above to access the full document. After log in, if you do not have the right authorization for this document, there will be instructions on what to do next.

Document Information

Modified date:
31 October 2022

UID

ibm16831789