page-brochureware.php
QRadar 101 A one-stop experience to help you navigate through content available for supporting QRadar. Support Help Urgent Case Help
News and Notices Stay up to date with the latest changes in QRadar. 27 October QRadar 7.5.0 UP14 is released
QRadar Update

Administrators with 7.5.0 UP10 or later can upgrade to their QRadar deployment to 7.5.0 Update Package 14. This release includes performance enhancements, tiered storage for Data Nodes, UI improvements, rule test update to set magnitude, offense improvements, and resolves 24 reported issues from QRadar users. This release includes mitigations for CVEs to update the security posture of QRadar SIEM.

  QRadar Software 101
11 September QRadar 7.5.0 UP13 Interim Fix 2 is released
QRadar Update

Administrators with 7.5.0 UP13 can now apply Interim Fix 2 to their QRadar deployment. This Interim Fix release resolved three reported issues and includes remediations for 19 CVEs. For details, see the QRadar 101 Software page for release notes, download links, and more.

  QRadar Software 101
21 August QRadar 7.5.0 UP13 Interim Fix 1 is released
QRadar Update

Administrators with 7.5.0 UP13 can now apply Interim Fix 1 to their QRadar deployment. This Interim Fix release resolved three reported issues and includes remediations for 2 CVEs. For details, see the QRadar 101 Software page for release notes, download links, and more.

  QRadar Software 101
1 July QRadar 7.5.0 UP13 is released
QRadar Update

Administrators with 7.5.0 UP10 or UP11 (any interim fix level) can now upgrade directly to the 7.5.0 UP13 release. This release enhances Console-only failover improvements and optimized backup validation time. Offense tab now has a Timeline view of offenses, Magnitude-based ranking, or Host-based categorization. Admin tab updates for Unified Store & Forward, Domain management, centralized credentials, and resource restriction interfaces. Regex Custom Properties now allow multiple capture groups and literals in custom properties. Added SNMPv3 and snmpwalk polling for hosts. Enhanced partial search result visibility. The improved suggested regex for parsing, auto-population of Event ID and Event Category, and event parsing for several core DSM types.

  QRadar Software 101
27 June QRadar Investigation Assistant powered by watsonx.ai
App AI Monitoring

The QRadar Investigation Assistant powered by watsonx.ai uses Large Language Models (LLM) and Natural Language Processing (NLP) to help analysts while working with offenses. Crisp and accurate AI-generated offense summary helps to reduce false negatives caused by complex attacks that are not easily observable to the human eye, reduce the skills required for security analysts to understand complex incidents and attack vector, and boost analyst productivity by significantly reducing time spent on offense investigation. Additionally, the app provides AI-generated short-term and long-term recommendations help take decisive actions against critical threats.

Click Here to get the app Read the blog
18 June QRadar 7.5.0 UP12 IF2 is released
QRadar Update

Administrators with 7.5.0 UP12 can now upgrade to the 7.5.0 UP12 Interim Fix 2. This release resolves 3 important known issues for reference set search results, a backup issue, and a user interface issue, plus includes a Custom Property fix for a cache issue from 7.5.0 UP12 Interim Fix 1 when a custom property contains over 1000 values. Administrators can install IF2 to get the contents of IF1 and IF2 with a single update. For more information, see the QRadar Software 101 page for a link to the release notes and software download on IBM Fix Central.

  QRadar Software 101
15 May QRadar 7.5.0 UP12 is released
QRadar Update

Administrators with 7.5.0 UP10 or UP11 (any interim fix level) can now upgrade directly to the 7.5.0 UP12 release. This release enhances the search progress visualization, improves search performance for multi-tenant deployments with Reference Set filters, enhances search for Event Collectors by name, Data Node scattering improvements, Java 11 updates for protocols, and add creation date to the offense summary page and the offense search page.

  QRadar Software 101
14 May WinCollect 7.3.1 P4 is released
WinCollect Update

On 14 May, 2025 a new release of WinCollect 7.3.1 Patch 4 was posted to IBM Fix Central. This release 7.3.1-122 is a required update for users on 7.5.0 Update Package 12 and resolved two issues reported by users.

Download WinCollect 7.3.1 Patch 4 Release Note
28 Jan QRadar 7.5.0 UP11 is released
QRadar Update

Administrators with 7.5.0 UP8, UP9, or UP10 (any interim fix level) can now upgrade directly to the 7.5.0 UP11 release. This release updates the core operating system for QRadar from Red Hat Enterprise V8.8 to V8.10, updates Postgres from 11.7 to 16.2, and an Apache Struts update. Features such as Workflow Analyst App as the default dashboard, flow forwarding performance, new API functionality for assets and offense API responses in OSCF format, and more. The UP11 release resolves 39 Known Issues reported by users. Administrators who want to validate UP11 with the code signing script can get the latest version 1.0.2, which includes updated certificate bundle to validate UP11 and later software downloads from IBM Fix Central.

UP11 Code Signing 1.0.2 QRadar Software 101
14 Oct QRadar 7.5.0 UP10 is released
QRadar Upgrade

Administrators with 7.5.0 UP8 or UP9 can now upgrade directly to the 7.5.0 UP10 release. This release adds multiple features, such as a Light Mode toggle as a user preference, Parallel patching feature allows you to stage and upgrade all QRadar managed hosts in the deployment in an unattended manner and view the % updated for your deployment as a live status, and FISMA support adds IPv6 parsing, ingestion, search, and integration features across QRadar. This release also improves event and flow search stability and performance for large deployments, high query concurrency, and complex datasets by managing memory more effectively, as well as improving searching for IPv6 addresses, which are up to 200 times faster.

  QRadar Software 101
4 Oct Auto update flash notice
Outage Resolved

IBM has identified an issue where QRadar deployments may experience an outage of Event ingestion after the Auto Update released on 4 October 2024 is completed. Users reporting this issue were unable to see events in Log Activity or new offenses being generated. This issue is now resolved.

  Flash Notice
28 Aug AI Usage Dashboards
AI Monitoring Dashboard

Administrators can now better understand and enforce policy with the IBM Security QRadar Generative AI Content Extension. This content pack uses the URL Host custom property from several DSM types, along with reference maps, to monitor AI platform usage within the organization. The dashboard includes breakdowns by AI tool usage, hosts making the most requests to AI domains, Event Counts, Location, Top 10 Source IPs, Top 10 Destination IPs, Top 10 Users, and recent queries (events).

  Content Extension
16 July QRadar 7.5.0 UP9 can experience extended upgrade time
Warning Update

Administrators upgrading to 7.5.0 Update Package 9 may experience longer maintenance windows. A reported issue indicates a post-patch update script that takes longer than expected. Do not interrupt the upgrade or reboot an appliance before it is complete to avoid a system rebuild. A flash notice includes a command to help estimate the impact on upgrade timing. Administrators who wish to avoid this issue can wait for the re-release of 7.5.0 UP9, which is coming soon.

  Flash Notice
9 July QRadar 7.5.0 UP9 released
Update Features

IBM has released QRadar 7.5.0 Update Package 9, the recommended upgrade path for QRadar 7.5.0 UP7 users. This release introduces features like dark mode UI modernization, CIDR data types in reference sets, improved Data Nodes and Offline event forwarding, and Data Synchronization app enhancements. Additionally, 69 known issues from previous releases have been resolved. Administrators should review the Pulse app known issue and be aware that full HA data sync will be performed for HA secondaries.

  Software 101 page
Important 7.5.0 UP8 Flash Notice

IBM identified a replication issue for managed hosts on QRadar 7.5.0 Update Package 8 following the Auto Update from 21 June 2024. Users experiencing this issue reported problems with deploy changes. A workaround is available in the flash notice for administrators on 7.5.0 UP8 (any interim fix level).

 
Important Update
Flash Notice
4 June 7.5.0 UP8 Interim Fix 3 released

A replacement release is available on IBM Fix Central for QRadar 7.5.0 Update Package 8 Interim Fix 3, addressing six reported issues. This release replaces the removed 7.5.0 UP8 Interim Fix 2, which had a search performance issue. As interim fixes are cumulative, administrators can install 7.5.0 UP8 IF3 and receive all prior fixes.

 
Fix Update
QRadar Software 101
24 May QRadar 7.5.0 UP8 Interim Fix 2 removed

QRadar 7.5.0 Update Package 8 Interim Fix 2 was temporarily removed from IBM Fix Central due to a search performance issue identified as DT386246.

 
Issue Removal
Known Issue: DT386246
7 May QRadar Community Edition 7.5.0

The latest QRadar Community Edition is now available on QRadar 7.5.0 Update Package 8, running on Red Hat 8.8. This edition supports non-enterprise users, allowing them to run QRadar with a 100 EPS and 5,000 FPM license. Ideal for students, developers, hobbyists, and network security teams to run QRadar at home. For details, visit the QRadar Community Edition webpage.

 
Community New Release
QRadar Community Edition
7 May Log Source Management app 7.0.9

The new release of QRadar Log Source Management allows bulk updates to name templates, disables Target Event Collect for Syslog sources, includes security updates, and resolves an error for users without sources in their security profile. Learn more on the QRadar Community Edition page.

 
App Update
QRadar Community Edition
25 March QRadar 7.5.0 Update Package 8 released

QRadar 7.5.0 Update Package 8 is now available on IBM Fix Central, updating the operating system baseline from RHEL 7.9 to RHEL 8.8. Administrators should ensure /storetmp has 10GB free space, review for LUKS encrypted disks, and follow post-install procedures for HA appliances. Visit the Software 101 page for more details and release notes.

 
Release RHEL Update
QRadar Software 101
25 March WinCollect 7.3.1 P3 is released

Managed WinCollect agents planning to upgrade to QRadar 7.5.0 Update Package 8 should install the latest WinCollect 7.3.1-43. After upgrading, download and install the SFS file for WinCollect 7.4.1-43. For more information, see the WinCollect 7 page on QRadar 101.

 
WinCollect Update
Get WinCollect 7.3.1 P3 (7.3.1-43)
25 March Hosts with LUKS encryption cannot be upgraded to 7.5.0 Update Pack 8

As the release of QRadar 7.5.0 Update Package 8 approaches, QRadar SIEM development has identified a known issue where hosts with LUKS encryption cannot be upgraded to 7.5.0 Update Pack 8. This is a RHEL limitation for QRadar 7.5.0 Update Package 8. Customers who want to upgrade to 7.5.0 Update Pack 8 from 7.5.0 Update Pack 7 should ensure that no hosts in the deployment have LUKS encryption. For more information, see the Flash Notice.

 
WinCollect Update
QRadar Flash Notice

Version information

We can have some text here.

QRadar v7.5.0 QRadar v7.4.3 QRadar v7.4.2 QRadar v7.4.1 QRadar v7.4.0

What’s New in QRadar v7.5.0?


Operational improvements

Operating system updated to Red Hat® Enterprise Linux® version 7.9. Local Only authentication allows administrators to prevent unintended access to users with accounts in external authentication systems. Use secure boot to ensure that only trusted kernels and kernel modules are loaded. Two new offense rule tests: ‘when an offense is closed’ and ‘when an offense is modified’. A new AQL OFFENSE_TIME function to increase the speed of your offense queries. A new AQL DISTINCTCOUNT function to return the unique count of the value in an aggregate. Encryption of managed hosts enabled by default.

Flow Improvements

Support for IPFIX bidirectional flows. Multi-threaded processing for external flow sources. Sequence number verification. Support for Network Address Translation fields from IPFIX and NetFlow v9. New application determination algorithms. Support for more fields from AWS VPC flow logs. Alias Autodetection field is renamed to DNS lookup for Alias Autodetection. Flow direction algorithms are now applied at the beginning of the flow parsing process. You can no longer delete the ‘Uncategorized’ category for tagged flow fields from your system. Only relevant IPFIX fields are encoded into the payload and extra fields are added as TLV elements.
What is Changed or Removed?

The hashing algorithm default is changed to SHA-512 for all Ariel hashing. Several algorithms, such as MD-2, MD-5, HMAC-MD5 are removed.

Network inspection performance. Performance improvements for the QRadar Network Insights 6500 appliance. Modified process for identifying file types. More integration with IBM X-Force. Improved application detection. Data aggregation and segmentation improvements. Some inspectors are no longer supported, such as web domain, Myspace protocol, and SPDY. During the upgrade to QRadar Incident Forensics 7.5.0, case data is exported and then imported back into the QRadar Incident Forensics managed host. As a result, the upgrade process takes longer to complete than in previous releases. Vulnerability data scores and metric values are returned as CVSS version 3.0 or 3.1.

QRadar v 7.5.0


View release notes by version

Upgrade Guide

What’s new

QRadar events and webinars


Events and webinars are hosted by QRadar experts to discuss technical topics or present content teams feel is beneficial to users and administrators.

May 29, 10:00 AM (ET) IBM QRadar Unlocked: What’s New & Next Ready to peek behind the curtain of QRadar? We’re hosting a live session packed with fresh features, roadmap reveals, and real-world stories from the front-lines of cybersecurity.

In this session, we’ll be revealing the roadmap, demoing new features, discussing how customer’s are leveraging QRadar, and taking your questions.
June 12, 1:00 PM (CEST) | 7:00 AM (ET) IBM QRadar User Group DACH (40): More efficiency in a QRadar based SOC

We look forward to welcoming you to the 40th IBM QRadar User Group Event on June 12th, starting at 1:00 PM in IBM Vienna, Obere Donaustraße 95, 1020 Vienna! This is a live and online event.
Oct 6, 9:00 AM to 3:00 PM (ET) IBM TechXchange Conference 2025

Get hands-on with the newest tech, meet experts, and code with your peers.

Explore QRadar 101

QRadar home

Return to the QRadar 101 homepage

Applications

Learn about QRadar apps

Deploy changes

Learn about deploying changes to QRadar

Disk Space

Learn about managing QRadar disk space

Software

Download software for QRadar

Support Assistance

Read our support policies

Support tools

Browse CLI tools to help with troubleshooting

Technotes

Browse a directory of our technical notes

Installs and Upgrades

Learn about installing and upgrading QRadar

Known issues

See current and fixed issues with QRadar


image

IBM prides itself on delivering world class software support with highly skilled, customer-focused people.


Return to 101 home

Contact Support

Asia Pacific Europe Latin America North America Middle East and Africa