Troubleshooting
Problem
Users have issues when they try to import custom content from one QRadar environment to another due to conflict with log source extensions.
The following error message is seen when the user attempts to install the extension from the UI:
An error occurred. See console logs for details.
Cause
The import content includes a log source extension that already exists with the same name on the console where they are trying to import the content to.
Diagnosing The Problem
Errors of "conflicts with the existing log source type" are seen in /var/log/qradar.log:
com.ibm.si.content_management.ContentCustom: [ERROR]
Conflict: The inbound custom log source type with Name: GuardicoreCustom,
ID: 4001, and UUID: 09ec6438-80be-4dc1-84a1-a19631fee5ee conflicts
with the existing log source type with Name: GuardicoreCustom,
ID: 4003 and UUID: e0a3cc1c-fd2c-4069-a468-6e30b1444f38
In this example, the error makes reference to a log source extension with name GuardicoreCustom that exists on both QRadar consoles with the same name but different UUID.
On the QRadar console from where the data is exported, the UUID is:
ID: 4001, and UUID: 09ec6438-80be-4dc1-84a1-a19631fee5ee
And on the QRadar console where the user is trying to import the content to, the UUID is:
ID: 4003 and UUID: e0a3cc1c-fd2c-4069-a468-6e30b1444f38
This is likely the result of a previous import.
Resolving The Problem
- SSH to the QRadar console where you want to import the data to as the root user.
- Go to the Admin tab.
- Click Log Source Extension.
- Locate the conflicting log source extension and select it.
- Click Edit, then change the name of the log source extension to something different, for example, from GuardicoreCustom to GuardicoreCustom_2:
- Save the changes.
Result:
The user is able to import the content without any error.
Document Location
Worldwide
[{"Type":"MASTER","Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000cwsyAAA","label":"Admin Tasks"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]
Was this topic helpful?
Document Information
Modified date:
14 May 2024
UID
ibm17148874