Question & Answer
Question
A new security content pack is available for IBM Security Privileged Identity Manager. This tech note outlines the changes and provides installation instructions for administrators.
Answer
Quick links
- What is in the IBM Privileged Identity Manager Security Content Pack?
- How do I install a security content pack?
- I have additional questions, where can I go for more information?
What is in the IBM Security Privileged Identity Manager Security Content Pack?
QRadar SIEM collects events from IBM Security Privileged Identity Manager using JDBC for standard auditing, authentication, and system events. This security content pack contains 5 new custom event properties for important fields that can be leveraged by administrators in reports or searches, which were not available in the original DSM release.
New Custom Event Properties added by the IBM Privileged Identity Manager Security Content Pack
Description | Regex for the custom event property |
Action Result | RESULT_SUMMARY: "(.*?)" |
Credential ID | EVENT_CATEGORY: "Credential.+?".+?ENTITY_NAME: "(.*?)" |
Lease DN | LEASE_DN: "erglobalid=([0-9]*?), |
Lease Expiry Time | LEASE_EXPIRATION_TIME: "([-: 0-9]+?GMT)" |
Resource Name | SERVICE_NAME: "(.*?)" |
How do I install a security content pack?
To install a security content pack, an administrator must download the RPM from IBM Fix Central, then install the content pack on the Console appliance. The Console replicates the changes from the install of the content pack to all managed hosts in the deployment.
Procedure
- Download the IBM Privileged Identity Manager Security Content Pack from the IBM Fix Central website for your QRadar version:
- For QRadar 7.1: Link to all QRadar 7.1 Security Content Packs
- For QRadar 7.2: Link to all QRadar 7.2 Security Content Packs
- Using SSH, log in to your Console as the root user.
- Copy the security content pack to the /tmp directory on the QRadar Console. Note: If space in the /tmp directory is limited, copy the fix pack to another location that has sufficient space.
- To install the security content pack, type one the following command:
- For QRadar 7.1, type: rpm -Uvh ContentPackage-CustomProperties-IBMSecurityPrivilegedIdentityManager-7.1-1432699262.x86_64.rpm
- For QRadar 7.2, type: rpm -Uvh ContentPackage-CustomProperties-IBMSecurityPrivilegedIdentityManager-7.2-1432699262.x86_64.rpm
- Log in to the QRadar Console as an administrator.
- Click the Admin tab.
Before you continue: Restarting the web server will restart the user interface and load the new custom event properties. This action will log out existing users, stop reports in progress, and halt event exports in process. It is recommended that administrators restart the user interface during a maintenance window for the appliance.
- Click Advanced > Restart Web Server.
- Click OK to restart the QRadar user interface.
Results
After the user interface restarts, the installation is complete. The administrator should review the IBM Security Privileged Identity Manager custom event properties to determine if any of the values need to be enabled, disabled, or optimized in the QRadar interface.
[{"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Integrations - IBM","Platform":[{"code":"PF016","label":"Linux"}],"Version":"7.1;7.2","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]
Was this topic helpful?
Document Information
Modified date:
02 April 2020
UID
swg21961191