IBM Support

Release of QRadar 7.2.5 Patch 2 (7.2.5.20150605140117)

Release Notes


Abstract

A list of the installation instructions and fixes for IBM Security QRadar 7.2.5 (7.2.5.20150605140117).

Content

If your deployment is installed with QRadar 7.2.4 or later, you can install fix pack 7.2.5-QRADAR-QRSIEM-20150605140117.

Note: The 7.2.5-QRADAR-QRSIEM-20150605140117 fix pack can upgrade QRadar 7.2.4 and above to the latest software version. However, this document does not cover all of the installation messages and requirements. For information on upgrading from QRadar 7.2.4 to QRadar 7.2.5, see the QRadar Upgrade Guide.


Before you begin

Ensure that you take the following precautions:

  • Back up your data before you begin any software upgrade. For more information about backup and recovery, see the IBM Security QRadar Administration Guide.
  • To avoid access errors in your log file, close all open QRadar sessions.
  • The fix pack for QRadar cannot be installed on a managed host that is at a different software version from the Console. All appliances in the deployment must be at the same software revision to patch the entire deployment.
  • Verify that all changes are deployed on your appliances. The patch cannot install on appliances that have changes that are not deployed.

About this task

Fix packs are cumulative software updates to fix known software issues in your QRadar deployment. QRadar fix packs are installed by using an SFS file. The fix pack can update any appliance that is attached to the QRadar Console that is at the same software version as the Console.


    Procedure
    1. Download the fix pack 7.2.5-QRADAR-QRSIEM-20150605140117 from the IBM Fix Central website: http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Security%2BSystems&product=ibm/Other+software/IBM+Security+QRadar+SIEM&release=7.2.0&platform=Linux&function=fixId&fixids=7.2.5-QRADAR-QRSIEM-20150605140117&includeSupersedes=0&source=fc
    2. Using SSH, log in to your system as the root user.
    3. Copy the fix pack to the/tmp directory on the QRadar Console.
      Note: If space in the /tmp directory is limited, copy the fix pack to another location that has sufficient space.
    4. Review the files in the /tmp directory for replication files that might be using up space unnecessarily, such as tx000XX.sql.
    5. If tx000xx.sql files are listed, type the following command to remove these files: rm tx*.sql
      This prevents a disk space issue from occurring in /tmp that can occur.
    6. To create the /media/updates directory, type the following command: mkdir -p /media/updates
    7. Change to the directory where you copied the patch file. For example, cd /tmp
    8. To mount the patch file to the /media/updates directory, type the following command: 
      mount -o loop -t squashfs 725_QRadar_patchupdate-7.2.5.20150605140117.sfs /media/updates
    9. To run the patch installer, type the following command: /media/updates/installer
      Note: The first time that you run the fix pack, there might be a delay before the fix pack installation menu is displayed.
    10. Using the patch installer, select all.

      The all option updates the software on all systems in your deployment. In HA deployments, primary HA appliances are patched and replicate the patch update to the secondary HA appliance.

      If you do not select the all option, you must copy the update to each appliance in your deployment and install the fix pack. If you manually install fix packs in your deployment, you must update your appliances in the following order:

      1. Console
      2. Event Processors
      3. Event Collectors
      4. Flow Processors
      5. Flow Collectors

      If your Secure Shell (SSH) session is disconnected while the upgrade is in progress, the upgrade continues. When you reopen your SSH session and rerun the installer, the patch installation resumes.
    11. After the patch completes and you have exited the installer, type the following command: umount /media/updates
    12. Administrators and users should clear their browser cache before logging in to the Console.


Results

A summary of the fix pack installation advises you of any managed host that were not updated. If the fix pack fails to update a managed host, you can copy the fix pack to the host and run the installation locally.

After all hosts are updated, administrators can send an email to their team to inform them that they will need to clear their browser cache before logging in to the QRadar SIEM interface.

Resolved issues



Since QRadar 7.2.5 is a cumulative release, the release notes listed below include fixes assigned to 7.2.5 and the issues resolved in 7.2.5 Patch 2. Note: Some APAR links in the table below might take 24 hours to display properly after a software release.

IBM Security QRadar
The following issues were corrected in IBM Security QRadar V7.2.5 Patch 2
Product Number Description
QRADARIV73889OFFENSE GENERATION UNEXPECTEDLY STOPS OCCURRING IN QRADAR
QRADARIV73895'APPLICATION ERROR' POP UP WHEN OPENING AN OFFENSE
IBM Security QRadar
The following issues were corrected in IBM Security QRadar V7.2.5 Patch 1
Product Number Description
QRADARIV73672THE QRADAR USER INTERFACE CAN BECOME INACCESSIBLE DUE TO THE TOMCAT SERVICE RUNNING OUT OF MEMORY
IBM Security QRadar
The following issues were corrected in IBM Security QRadar V7.2.5.
Product Number Description
QRADARIV42471WHEN CHANGING GLOBAL CONFIGURATION PASSWORD, IT MAY TAKE A LONG TIME TO COMPLETE.
QRADARIV43440UNABLE TO FILTER ON CLOSED OFFENSES.
QRADARIV46111RULE TEXT COUNTERS MIGHT RESET WHEN THE RULE TEST RELOADS.
QRADARIV46116THE HIGH AVAILABILITY (HA) WIZARD FAILS TO ADD A HOST BECAUSE THE IP ADDRESS IS ALREADY DEFINED IN THE SERVER HOST TABLE.
QRADARIV46417A HARMLESS ERROR MESSAGE MIGHT DISPLAY WHEN YOU APPLY A FIX PACK UPDATE TO YOUR QRADAR SYSTEM.
QRADARIV50522EMAIL NOTIFICATIONS FAIL IF THE CONFIGURED EMAIL ADDRESS CONTAINS A HYPHEN "-".
QRADARIV50564CHANGING FROM THE ALL USER ROLE TO THE ADMIN USER ROLE DOES NOT UPDATE THE EVENT OR FLOW LISTS DISPLAYED ON THE DASHBOARD TABLE.
QRADARIV50732LIST OF EVENTS DOES NOT DISPLAY PROPERLY DUE TO HTML PARSING ERROR WHEN YOU USE THE MICROSOFT INTERNET EXPLORER 8 WEB BROWSER.
QRADARIV50740PENDING AUTOMATIC UPDATES MIGHT INSTALL UNEXPECTEDLY WHEN YOU UPDATE A SCHEDULE ON THE UPDATES WINDOW.
QRADARIV51020UNABLE TO CREATE A LOG SOURCE ONLY OR NETWORK ONLY SECURITY PROFILE WITHOUT BOTH LOG SOURCES AND NETWORKS SPECIFIED.
QRADARIV54327SOURCE AND DESTINATION ASSET NAME COLUMNS DO NOT QUERY THE HOSTNAME COMPONENT OF THE ASSET PROFILE.
QRADARIV54471MODIFYING A REPORT TEMPLATE MIGHT NOT ALLOW USERS TO CHANGE THE END DATE OF THE REPORT BEYOND SEPTEMBER 16, 2010.
QRADARIV54685NETWORK I/O ISSUES ON A MANAGED HOST MIGHT GENERATE AN OUT-OF-MEMORY ISSUE ON THE CONSOLE.
QRADARIV54705ARIELCLIENT CONTAINS ADDITIONAL LINE FEED AT THE END OF FILE.
QRADARIV55696CANNED QUICK SEARCHES DO NOT SHOW IN MANAGE SEARCH RESULTS BUT CUSTOM QUICK SEARCHES DO.
QRADARIV56033PERFORMING A SORT OF SEARCH RESULTS FOR AN IN-PROGRESS SEARCH GIVES ERROR 'THIS QUERY HAS TIMED OUT AND IS NO LONGER VALID.
QRADARIV56451BULK ADD OF LOG SOURCES MAY GENERATE AN F5 ERROR ON THE UI.
QRADARIV57325DATA ACCUMULATION AND UNIQUE COUNT MAY NOT BE DISPLAYED FOR THE ADMIN ON SEARCHES CREATED BY NON-ADMIN USERS.
QRADARIV58681FILTERING ON A CUSTOM PROPERTY THAT CONTAINS THE SUBSTRING "ID:"RETURNS NO RESULTS.
QRADARIV59099INCORRECT HOST.TOKEN CAUSES EXTERNAL AUTHENTICATION TO FIRE FOR "SEC" USER.
QRADARIV59873ADDING CUSTOM EVENT PROPERTIES WITH CERTAIN SPECIAL CHARACTERS CAN CAUSE AN EXCEPTION WHEN FILTERING.
QRADARIV59990LOG ACTIVITY SEARCH SHOWS WRONG DATE WHEN THE DASHBOARD GRAPHS HAVEN'T FULLY LOADED AND VIEW IS PRESSED IN LOG ACTIVITY.
QRADARIV60091DHCPV6 FLOW TRAFFIC BEING PARSED WITH INCORRECT EVENT NAME AND LOW LEVEL CATEGORY.
QRADARIV60208AFTER AN UPGRADE TO QRADAR 7.2.2 Patch 2, NEW LOG SOURCES DO NOT AUTOMATICALLY DISCOVER ON MANAGED HOSTS.
QRADARIV60574ARIEL RIGHT CLICK API DOES NOT WORK ON ARIEL PROPERTIES.
QRADARIV61205APPLICATION ERROR IN MANY PAGES FOR USER WITH $ IN USERNAME.
QRADARIV61910SEARCHES THAT COMBINE HIGH AND LOW CATEGORY SEARCH VALUE FILTERS RETURN INCORRECT RESULTS.
QRADARIV62434X-FORCE RULES TRIGGER EVEN WHEN TARGETING TRUSTED (NON-MALICIOUS) DOMAINS.
QRADARIV62512UNABLE TO CHANGE LANGUAGE SETTINGS AS NON-ADMINISTRATOR USER.
QRADARIV630671705 APPLIANCES SHOW UP AS 1701 APPLIANCES IN THE SYSTEM AND LICENSE MANAGEMENT SCREEN OF THE UI.
QRADARIV63125ADDING A SECONDARY TO A MANAGED HOST MAY FAIL DUE TO /STORE BEING BUSY ON THE SECONDARY.
QRADARIV63420ASSETPROFILER ERRORS IN QRADAR.LOG THAT REFER TO MESSAGEMARSHALLERV2.
QRADARIV63466THE 'EVENT PROCESSOR' SEARCH FILTER DOES NOT WORK WHEN SETUP IN RULES.
QRADARIV63939SEARCHES AND/OR REPORTS THAT CONTAIN THE COLUMN 'SOURCE ASSET NAME' AND ARE GROUPED BY SOURCE IP WILL RETURN 'NONE'.
QRADARIV64549IPFIX AND NETFLOW V9 ONLY READS 16-BIT AND NOT 32-BIT ASN NUMBERS.
QRADARIV64741QRADAR SOFTWARE ONLY INSTALLATION ON CUSTOMER SUPPLIED HARDWARE WITH XX28 SPECIFICATIONS MAY FAIL DURING SETUP.
QRADARIV64777REPORTS RETURN DIFFERENT DATA WHEN RUN AGAINST RAW DATA VERSUS A SCHEDULED/ACCUMULATED DATA REPORT.
QRADARIV65085WHEN LOGGING INTO THE QRADAR USER INTERFACE, CERTAIN DASHBOARD ITEMS SHOW AN ERROR MESSAGE.
QRADARIV65502RULES THAT USE 'INCLUDE DETECTED EVENT FROM THIS ATTACKER FROM THIS POINT FORWARD' ARE NOT ADDING NEW EVENTS TO THE OFFENSE.
QRADARIV65584WHEN APPLYING A LOG SOURCE EXTENSION TO A LOG SOURCE TYPE, THE USER INTERFACE APPEARS TO NOT APPLY THE CHANGE SUCCESSFULLY.
QRADARIV65935OFFENSE SEARCH 'SAVE CRITERIA' OPTION THAT CONTAINS A 'SOURCE NETWORK' FUNCTIONS CORRECTLY BUT DOES NOT DISPLAY PROPERLY.
QRADARIV66213NEWLY CREATED QRADAR DASHBOARDS ARE ACCESSIBLE TO ALL USERS WITH THE SAME ASSIGNED USER ROLE.
QRADARIV66756UNABLE TO LOAD THE 'LOG SOURCES' PAGE IN THE QRADAR UI AFTER PATCHING FROM 7.1.2.X TO 7.2.X.
QRADARIV67083RULES ARE NO LONGER ASSOCIATED TO OFFENSES AFTER A SOFT CLEAN SIM IS PERFORMED.
QRADARIV67212HOSTCONTEXT SERVICE DOES NOT AUTOMATICALLY RESTART AFTER DAYLIGHT SAVINGS TIME CHANGE.
QRADARIV67219EMPTY PLUG-INS OPTION ON ADMIN TAB IN THE QRADAR USER INTERFACE.
QRADARIV67325SNMP DAEMON IS NOT ENABLED ON HIGH AVAILABILITY SECONDARY.
QRADARIV67522THE REMOVE ITEM OPTION FROM WITHIN A TIME SERIES GRAPH DOES NOT ALWAYS WORK AS EXPECTED IN CHROME WEB BROWSER.
QRADARIV67755QRADAR DATA BACKUPS MIGHT FAIL TO RUN SUCCESSFULLY ON MANAGED HOSTS.
QRADARIV67807THE ARIEL RIGHTCLICK.PROPERTIES API DROPS THE '\' OR '$' CHARACTERS IN EVENT PROPERTIES.
QRADARIV67847FILTERED NETWORK ACTIVITY SEARCHES MAY RETURN UNEXPECTED RESULTS.
QRADARIV67939SILENT INSTALLS DO NOT WORK IN 7.2.4.
QRADARIV68011AN 'APPLICATION ERROR' POP UP WINDOW OCCURS WHEN CREATING A FLOW RULE THAT TESTS AGAINST REFERENCE TABLE DATA.
QRADARIV68343APPLYING QRADAR PATCH .SFS FAILS ON HIGH AVAILABILITY SECONDARY.
QRADARIV68596'AN ERROR HAS OCCURRED. REFRESH YOUR BROWSER...' MESSAGE WHEN ATTEMPTING TO DISABLE OR DELETE A RULE IN QRADAR.
QRADARIV68877TIME ZONE DATA DISPLAYED WITHIN QRADAR IS NOT ACCURATE FOR SOME TIME ZONES.
QRADARIV69168SAVED SEARCHES WITH SPECIAL CHARACTERS CAUSES DASHBOARDS TO DISAPPEAR.
QRADARIV69695WHEN DASHBOARDS ARE ADDED TO USER ROLES, THOSE USERS WILL NO LONGER SEE THE DEFAULT DASHBOARDS.
QRADARIV69750IDENTITY HOSTNAME IS BEING POPULATED BY USERNAME IN OFFENSE.
QRADARIV69817QFLOW CRASHES IF PACKET SOURCE ADAPTOR IS DISABLED.
QRADARIV69895UNABLE TO RESTORE CONFIG BACKUP FOR NON-ENGLISH UI.
QRADARIV70515EVENTPROCESSOR FILTER IN ADVANCED QUERY AND RESTAPI QUERIES ALL EVENT PROCESSORS WHEN SPECIFYING A SPECIFIC EVENT PROCESSOR.
QRADARIV70522'ERROR: NULL VALUE IN COLUMN' WHEN ADDING A NEW ADMIN USER ACCOUNT WITH EXTERNAL AUTH AND NO PASSWORD IS ENTERED.
QRADARIV70525RESPONSE TIME WHEN CONFIGURING A LOG SOURCE IS VERY SLOW WHEN USING WITH CHROME.
QRADARIV70601ARIEL ERROR WHEN FILTERING ON A SORTED, AGGREGATED COLUMN.
QRADARIV71009DELETING REFERENCE SETS USED IN RULES FAILS, BUT DOESN'T WARN WHY.
QRADARIV71013RE-EDITING REPORT DESCRIPTION SHOWS HTML </BR>.
QRADARIV71265DASHBOARD LEGENDS BLEEDING HTML CODE IN TOOLTIP.
QRADARIV71266DSM JAR FILES ARE NOT BEING PROPERLY RESTORED FROM A CONFIG BACKUP.
QRADARIV71980'DOMAIN' DOES NOT WORK AS A SEARCH FILTER WHEN USING THE QRADAR ADVANCED SEARCH FUNCTIONS.
QRADARIV72129'AN INVALID CURSOR WAS PROVIDED TO THE QUERY. PLEASE TRY AGAIN' WHEN A LOG OR NETWORK ACTIVITY SEARCH IS PERFORMED.
QRADARIV72736RESTAPI EVENTS ARE DISPLAYING AS 'UNKNOWN' EVENTS.
QRADARIV72903SYSTEM NOTIFICATION ERROR 'OUT OF MEMORY DISCOVERED FOR HOSTCONTEXT' DURING BACKUP PROCESS.
QRADARIV72934NULLPOINTEREXCEPTION IN QRADAR LOG FILES CAUSED BY AN INVALID REGULAR EXPRESSION (REGEX) IN A RULE SEARCH FILTER TEST.
QRADARIV73043THE /STORE/TRANSIENT PARTITION DOES NOT GET RE-MOUNTED AFTER PERFORMING A FACTORY RE-INSTALL USING THE 7.2.4 ISO.
QRMIV69656QRM MULTILINE LOG MESSAGE PRODUCES EXCESSIVE EVENTS IN QRADAR.
QVMIV73452SCHEDULED SCANS DO NOT APPEAR IN THE SCHEDULED SCANS CALENDAR.
QVMIV70824AUTOMATIC POST SCAN REPORTS ARE NOT BEING GENERATED.
QVMIV67786ERROR MESSAGE RETURNED WHEN ATTEMPTING TO UPLOAD A QVM LICENSE.



Where do I find more information?
If you have additional questions or some of this content is not clear, you can see the QRadar forum or contact customer support:

[{"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Documentation","Platform":[{"code":"PF016","label":"Linux"}],"Version":"7.2","Edition":"All Editions","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
10 May 2019

UID

swg27045959