QRadar Hostname DNS is not being resolved



An IP address seen in Log Activity is not resolving hostnames, despite the nslookup command line can resolve DNS lookup for same IP.


  1. Log in to the QRadar interface.

  2. Click Log Activity tab.

  3. Using right-click an IP address >More Options >Information>DNS 

Results: The lookup gave no result and instead of a hostname an IP address was resolved.

  1. Log in to the Console using an SSH session.

  2. Type the command nslookup with an IP Address.
    Example nslookup

Results: This command returns as the hostname.

Resolving The Problem

To resolve this issue
  1. Check the DNS entries in QRadar
    • QRadar Versions 7.2.8 and 7.3.2
      • On all the appliances check the entries in /etc/resolv.conf to confirm that the correct DNS values are correct.
    • QRadar Versions 7.3.0 and 7.3.1
      • Check the Console entries in /etc/resolv.conf.masq are correct.
      • Check the Managed Host entries in /etc/resolv.conf are correct.
  2. Check the DNS server to verify that it is configured correctly or that the DNS server QRadar is pointing to is correct.

Where do you find more information?

