IBM Support

QRadar: Troubleshooting graph data in the QRadar Deployment Intelligence (QDI) application

Troubleshooting


Problem

The graph data in health metrics from the QRadar Deployment Intelligence (QDI) app like "License and Event Rate" and "License and Flow Rate" is not displayed. This issue can be caused by changes to Customs Event Property (CEP) regular expressions, duplicate properties with the same name, or if the properties associated to the Health Metrics Log Source Type in QRadar are disabled. All of these issues can be a cause to why graph data does not display as expected.

Symptom

Although event and flow are displayed in Log activity and Network Activity tabs, QID widgets, such as License and Event Rate, License and Flow Rate, or Top 5 Hosts widgets do not display graph data in Dashboard of the QDI application.

image-20181204155540-4
Figured 1: Graph data is not displayed from managed hosts.

Cause

The lack of license metrics can indicate that the required custom properties used by the QDI application might be disabled, modified, or deleted. Custom Properties for the Health Metrics log source type are required for graph data to populate in the QDI application dashboard.

The most common cause of missing graph data:

  1. The Custom Event Properties for Health Metric data has been disabled.
  2. A required Custom Event Property for QID health metrics has been duplicated with the same name or reassigned.
  3. A required Custom Event Property for QID health metrics has been deleted.
  4. An issue with application polling for events from the QRadar API. View the poll.log for error messages that can indicate an issue.

Resolving The Problem

  1. Log in to the QRadar user interface as an administrator.
  2. Click the Admin tab.
  3. Click Custom Event Properties icon.
  4. Search for health metrics and verify all the Custom Event Properties are Enabled.image-20181212205326-1
  5. Click Log Activity tab.
  6. Click Search > New Search.
  7. Scroll to Column Definition
  8. In the Column Definition field, click > to move the following values from Available Columns to Columns:
    1. Component Name (custom)
    2. Component Type (custom)
    3. Deployment ID (custom)
    4. Element (custom)
    5. Hostname (custom)
    6. Metric ID (custom)
    7. Value (custom)
  9. In the Search Parameters field, use the following search parameters:
    1. Parameter is Log Source (Indexed)
    2. Operator is Equals
    3. Log Source Filter is Health Metrics-2
      image-20181212210852-4
  10. Click Add Filter
  11. Click Filter.
    image-20181212211511-1
  12. Search should return results to validate that data is incoming for the Health Metrics log source.image-20181212211715-2
  13. Click the Admin tab.
  14. Click the Custom Event Properties icon.
  15. Verify duplicate Custom Event Properties do not exist with the same property names:
    1. Component Name (custom)
    2. Component Type (custom)
    3. Deployment ID (custom)
    4. Element (custom)
    5. Hostname (custom)
    6. Metric ID(custom)
    7. Value (custom)
  16. If duplicates exist for a Custom Event Property that have the same name, administrators might need to disabled any duplicates.
  17. After you disable duplicate custom event properties, return to the Admin tab and click Deploy Changes.

    Results
    Wait for the deploy to complete. It might take up to 30 minutes for the graphs to show data in the QDI application. If you continue to experience issues, you can use the recon utility to view the poll.log for the QDI application or you can contact QRadar Support for assistance.

[{"Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000cwt3AAA","label":"QRadar Apps"}],"ARM Case Number":"","Platform":[{"code":"PF016","label":"Linux"}],"Version":"All Version(s)"}]

Document Information

Modified date:
15 March 2021

UID

ibm10743989