IBM Support

Release of QRadar Packet Capture SFS 7.4.3 (Build 496)

Release Notes


Abstract

A list of the installation instructions and resolved issues list for the release of IBM Security QRadar Packet Capture 7.4.3 (Build 496).

This software is intended for updates of QRadar Packet Capture and Packet Capture Data Node appliances, as well as for QRadar Packet Capture and Packet Capture Data Node installations on your own hardware.

Content

About

QRadar Packet Capture software updates use an SFS file, and can update an existing QRadar Packet Capture software or appliance installation to the latest version. These updates are cumulative. 


Requirements
Read the following information before you install the software:

  • QRadar Packet Capture 7.4.3 (Build 496) requires Red Hat Enterprise Linux (RHEL) 7.9. You must install RHEL 7.9 before you install QRadar Packet Capture. 
  • You must have QRadar Packet Capture 7.2.8 (any patch version) or later to install this update.
  • Software installs are NOT supported on a virtual machines (VMs). 
  • Complete the update during a scheduled maintenance window. While the system is updating, services do not run and network packets are not recorded. The update typically completes in about 1.5 hours. You can capture on one QRadar Packet Capture appliance while the software is being updated on another appliance.
  • To avoid access errors in your log file, close all open QRadar Packet Capture sessions.
  • Google Chrome 44.0 and Mozilla Firefox ESR 38.8 and later browsers are supported. Microsoft Internet Explorer 11 is not supported for QRadar Packet Capture appliances.
  • Any search output directories in /extraction that are older than 6 hours are removed.
  • If the Search store is full, any search output directories that are older than 3 hours are removed.

Instructions for installing QRadar Packet Capture 7.4.3 (Build 496)

Installation instructions are provided in the QRadar Packet Capture Quick Reference Guide on IBM Docs. 

Before you install QRadar Packet Capture, you must install Red Hat Enterprise Linux V7.9. To ensure that only the OS partition is updated and that existing packet captures are not affected by the installation, follow the documented procedure.

Procedure

1. Install and configure Red Hat Enterprise Linux V7.9.

2. Download the QRadar Packet Capture software file from the IBM Fix Central website:

3. Upgrade the QRadar Packet Capture software.


Issues resolved in QRadar Packet Capture 7.4.3 (Build 496)
Product Component Number Description
QRADAR  SECURITY BULLETIN CVE-2020-8252

Security Bulletin: Node.js as used by IBM Security QRadar Packet Capture contains multiple vulnerabilities







Where do I find more information?


[{"Type":"MASTER","Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000cwszAAA","label":"Install"},{"code":"a8m0z000000cwtdAAA","label":"Upgrade"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"7.4.3"}]

Document Information

Modified date:
07 October 2021

UID

ibm16493401