IBM QRadar: Principais Comandos e Arquivos

From Wiki
Revision as of 11:09, 3 February 2025 by Ebasso (talk | contribs) (→‎Principais arquivos)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

Principais arquivos

A instalação padrão fica no diretório:

/opt/qradar/
|- bin/
|  |- ariel_query                     -> Run a Ariel query from command line.
|  |- apply_appliance_tunings.pl      -> Apply Appliance Tunings settings
|  |- logrun.pl                       -> Send logs to qradar
|  |- qchange_netsetup                -> Realiza a troca de IP, DNS, ...
|- conf/
|  |- nva.conf                        -> Um dos principais arquivos e configuração do QRadar 
|- support
|  |- qappmanager                     -> verify status of all apps
|  |- recon                           -> Conecta ao container rodando a aplicação "recon connect <id>"
|  |- threadTop.sh                    -> thread like Top command, para aplicativos do QRadar
|- upgrade
|  |- util                     
|  |  |- setup
|  |  |  |- upgrades
|  |  |  |  |- do_deploy.pl           -> deploy events for 
|- conf
/store                                -> is used as directory for DB, Config. deployment files, and all stored events and flows data.

Commands

ariel_query

ariel_query --no-verify -u admin --output table --query "select QIDNAME(QID) from EVENTS limit 10"

Ver também