IBM Support

QRadar Suite (Cloud Pak for Security) - Which logs to check for troubleshooting Data Sources

How To


Summary

The Technote provides information on which logs to refer to for troubleshooting a Data Source.

Steps

For QRadar Suite (Cloud Pak for Security) onPrem you will need to have administrator access to your RHOCP cluster at the command line or Web User Interface.
Refer to the udi-udiworkers pods running under the namespace where QRadar Suite (Cloud Pak for Security) is installed.
The following command shown in the example will display the last 5 entries of logs and will tail the logs.
Tailing the logs allows you to see new entries generated when you operate or interact with the Data Source.
Replace <CP4S-NAMESPACE> with the namespace where QRadar Suite (Cloud Pak for Security) is installed.
oc logs -n <CP4S-NAMESPACE> -lname=udi-udiworkers --tail 5 -f
If an Edge Gateway or App Host is used in the data source connection then refer to the logs on that device.

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU048","label":"IBM Software"},"Product":{"code":"SSTDPP","label":"IBM Cloud Pak for Security"},"ARM Category":[{"code":"a8m0z0000001jPEAAY","label":"Data Source"}],"ARM Case Number":"TS016971313","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]

Document Information

Modified date:
15 August 2024

UID

ibm17165587