IBM Support

Collect MustGather Data for IBM Security QRadar SOAR Playbook Troubleshooting

Troubleshooting


Problem

Collect troubleshooting data for problems with IBM Security QRadar SOAR playbooks. Gathering this information before contacting IBM support will help familiarize you with the troubleshooting process and save you time.

Resolving The Problem

Playbook problems
 
For problems with playbooks, gather the following information:
 
  • Describe the problem providing screen shots and other contextual information so the problem can be accurately relayed to IBM Support
  • Enable functional logging by going to System Settings -> System Diagnostics -> Functional logging
    • Enable and choose Playbooks from the list of functional areas
System Settings
 
Functional logging
  • Does the workflow invoke an application or function?
  • Enable debug logging for the application hosted on an App Host
    • Go to App -> Details -> Configuration -> app.config
      • Edit the app.config adding loglevel = DEBUG under the [resilient] heading
      • Click on Save and Push Changes
      • Allow the app to restart

  • Enable debug logging for the application hosted on an integration server
[resilient]
loglevel = DEBUG
  • Reproduce the problem
  • What date and time did the problem occur or did you reproduce the problem?
    • What time zone is the reported time?
  • Provide the incident or case ID
  • What is the name of the playbook?
  • Take a screen shot of the Playbook Progress screen
    • In the affected incident click on Playbook Progress
    • Expand the section by clicking on the twistie and take a screen grab
    • Click on "View full playbook activities" and get screen grabs of all pages scrolling from to the bottom of the page
Playbook Progress
 
Twistie
 
View full playbook activities
 
View full playbook activities
 
sudo -u postgres -i psql co3 -c "select container, count(*), sum(length(msg)) as bytes, max(length(msg)) as bytes from monapp.activemq_msgs group by container order by container" on the SOAR server CLI
 

Document Location

Worldwide

 
 

[{"Type":"MASTER","Line of Business":{"code":"LOB77","label":"Automation Platform"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSA230","label":"IBM Security QRadar SOAR"},"ARM Category":[{"code":"a8m0z000000cw4bAAA","label":"Resilient Core"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]

Document Information

Modified date:
20 July 2026

UID

ibm17145826