Carbon Black Cloud: How To Troubleshoot QRadar Integration Issues
book
Article ID: 291692
calendar_today
Updated On:
Products
Carbon Black Cloud Endpoint Standard (formerly Cb Defense)
Issue/Introduction
Here are some steps to follow when troubleshooting a QRadar SIEM integration through initial setup or one that has stopped receiving events from the console with no changes to the environment.
Environment
Carbon Black Cloud Console: All Versions
VMware Carbon Black Cloud App for IBM QRadar: Version 2.0.0
Verify that you are using the most up-to-date version of the CBC QRadar app
Confirm that API keys and permissions are configured properly in the Carbon Black Cloud console, and that the correct API key is used in the Qradar app configuration