IBM Support

QRadar: How to restore UBA 4.0.1 after installing UBA 4.1.X in a non-UBI compliant environment

How To


Summary

This technical note provides guidance for administrators who accidentally install a UBI version of the User Behavior Analytics (UBA) app, such as UBA V4.1.9 on a non-UBI compliant QRadar environment.

Objective

The goal of this procedure is for administrators to stop, backup, uninstall, then reinstall the correct application version to preserve your UBA data.

Environment

This technical note is intended for administrators who accidentally install a newer version of the User Behavior Analytics app on an older version of QRadar. As the newer application requires the Universal Base Image framework that does not exist on older versions, the administrator might need to back up their data, then reinstall the correct UBA app.

Steps

Before you begin
  • To complete this procedure, you must have both admin and root access in QRadar.
  • Administrators who have the QRadar Assistant application can start or stop applications from the user interface, use the qappmanager, or the QRadar gui_app_framework API to stop running applications.
  • Always confirm you have the correct application ID to ensure you are making changes to the correct application. If you are unsure of this procedure or you want clarification on a step, contact QRadar Support before you make any changes.
Procedure
 
  1. Stop the UBA 4.1.x app from either QRadar Assistant application, the API, or qappmanager utility.
  2. Confirm the application ID of the User Behavior Analytics app. 
    Note: In this procedure, the application ID for the UBA app is 4100 and 2222 when reinstalled. If you uninstall and reinstall an app, the application ID can change to a new value during installation.  
  3. To create backup of existing data, type the following command: 
    cp -rp /store/docker/volumes/qapp-4100/ /store/ibm_support/6846553/qapp-4100
  4. Uninstall UBA 4.1.x from Console user interface. 
    Note: When prompted, select Revert all unless specific changes to rules need to be retained.
  5. Install UBA version 4.0.1.
  6. Verify that the UBA application is accessible in the user interface.
  7. Verify the new application ID assigned to the User Behavior Analytics app:
    /opt/qradar/support/qappmanager
  8. Stop the UBA app.
  9. Delete the existing /store/docker/volumes/qapp-2222 directory.
    Note: Do not delete the qapp-4100 backup folder until you confirm that the new UBA app is functional.
  10. Type the following commands to copy your existing data and restore it to a new qapp-2222 directory:
    cp -rp /store/ibm_support/6846553/qapp-4100 /store/docker/volumes/qapp-2222 

    Results
    The procedure is complete. Administrators can confirm that the data is restored in the user interface and no errors display. If you continue to experience issues, contact QRadar Support for assistance.

Related Information

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSV4BL","label":"IBM QRadar"},"ARM Category":[{"code":"a8m0z000000cwt3AAA","label":"QRadar Apps"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"7.3.0;7.4.0"}]

Document Information

Modified date:
31 July 2023

UID

ibm16846553