IBM Support

QRadar: DNS Update records for MS Windows Server 2000/2003 DHCP Server Logs have the Source IP octets backwards

Troubleshooting


Problem

DNS Update records for MS Windows Server 2000/2003 DHCP Server Logs have the Source IP octets backwards

Symptom

Customers have reported some the IP addresses in Microsoft DHCP Server Logs are displayed in reverse order in the QRadar UI. For example, certain records for a computer with an IP address of 192.168.1.1 will be recorded shows as 1.1.168.192).

Cause

We have contacted Microsoft about this issue and it is related to Microsoft OS core bugs 1569319/1955943. The records are written out in reverse order prior to our agent collection and this is resolved in Microsoft Windows Server 2008.

Resolving The Problem

There is no workaround for IBM QRadar SIEM. Microsoft has requested that customers upgrade to to Windows Server 2008 to resolve this issue.


Where do you find more information?



[{"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Integrations - 3rd Party","Platform":[{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"7.2","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
21 June 2018

UID

swg21622693