This technical note provides guidance for administrators who accidentally install a UBI version of the User Behavior Analytics (UBA) app, such as UBA V4.1.9 on a non-UBI compliant QRadar environment.
- To complete this procedure, you must have both admin and root access in QRadar.
- Administrators who have the QRadar Assistant application can start or stop applications from the user interface, use the qappmanager, or the QRadar gui_app_framework API to stop running applications.
- Always confirm you have the correct application ID to ensure you are making changes to the correct application. If you are unsure of this procedure or you want clarification on a step, contact QRadar Support before you make any changes.
- Stop the UBA 4.1.x app from either QRadar Assistant application, the API, or qappmanager utility.
- Confirm the application ID of the User Behavior Analytics app.
Note: In this procedure, the application ID for the UBA app is 4100 and 2222 when reinstalled. If you uninstall and reinstall an app, the application ID can change to a new value during installation.
- To create backup of existing data, type the following command:
cp -rp /store/docker/volumes/qapp-4100/ /store/ibm_support/6846553/qapp-4100
- Uninstall UBA 4.1.x from Console user interface.
Note: When prompted, select Revert all unless specific changes to rules need to be retained.
- Install UBA version 4.0.1.
- Verify that the UBA application is accessible in the user interface.
- Verify the new application ID assigned to the User Behavior Analytics app:
- Stop the UBA app.
- Delete the existing /store/docker/volumes/qapp-2222 directory.
Note: Do not delete the qapp-4100 backup folder until you confirm that the new UBA app is functional.
- Type the following commands to copy your existing data and restore it to a new qapp-2222 directory:
cp -rp /store/ibm_support/6846553/qapp-4100 /store/docker/volumes/qapp-2222
The procedure is complete. Administrators can confirm that the data is restored in the user interface and no errors display. If you continue to experience issues, contact QRadar Support for assistance.
Was this topic helpful?
31 July 2023