How to delete specific events [GDPR]
Hi Community,
I was asked a question I could not answer quickly. Is it possible to delete specific events that should not be on QRadar? If an application mistakenly sent an event with credit card numbers, but obfuscation was not configured, I wanted to delete those events. Through the UI there is nothing related to event removal. How about through the CLI?
I know that there is /opt/qradar/bin/runjava.sh com.q1labs.ariel.io.ACP, but I couldn't really delete the events.
I tried to erase some events but it didnt work. I have some events, where the user „alex“ is included.
/opt/qradar/bin/runjava.sh com.q1labs.ariel.io.ACP -n events -b "2018/07/16 15:00:00" -e "2018/07/16 15:28:00" -q "username ilike 'alex'" -u admin -d /store/new_ariel1
I ran the command above and got the following:
AQL criteria: [username ilike 'alex'] User: admin Copying: [events] to /store/new_ariel2 Timeline from Mon Jul 16 15:00:00 CEST 2018 to Mon Jul 16 15:28:00 CEST 2018 Trying to copy dir: /store/ariel/events/records/2018/7/16/15[18-07-16,15:00:00] Reader started ... Processing interval /store/ariel/events/records/2018/7/16/15/events~29_0~cba14a1d01a0418e~864a36edac47ff84~0[18-07-16,15:29:00] […] Reader stopped. Written 3 records, Skipped 398826 records
Completed copying dir: /store/ariel/events/records/2018/7/16/15[18-07-16,15:00:00]
The events were copied to /store/ariel/new_ariel2
I thought that the qradar would move the old events to /store/ariel/new_ariel2 and then filter out „alex“ from the original events at „/store/ariel/ .
If I run:
select username, count(*) as total from events where username ilike 'alex' group by username order by total desc limit 100 last 30 minutes
I am still able to see „alex“ on Qradar. Have I slipped up somewhere?
I also tried to move the content from /store/new_ariel2 to /store/ariel and found out that the events were duplicated. It seems that filtering did not work…
Thank you!
Best Regards,
Bruno
相關推薦
How to delete specific events [GDPR]
Hi Community, I was asked a question I could not answer quickly. Is it possible to delete specific events that should not be on QRadar? I
How To Handle Click Events In Android RecyclerViews
According to the documentation, a RecyclerView is a flexible view for providing a limited window into a large data set. If you have done any android dev
Google hack: Why it matters and how to delete your account
In June 2011, the world's biggest internet company launched what it hoped would become the world's biggest social network. And we aim to fix it," Google's
How to Delete using INNER JOIN with SQL Server?
https://stackoverflow.com/questions/16481379/how-to-delete-using-inner-join-with-sql-server You need to specify what table you are deleting f
Deleting a Mounted Folder The code example in this topic shows you how to delete a mounted folder by
The code example in this topic shows you how to delete a mounted folder by using theDeleteVolumeMountPointfunction. For more information, seeCreating Mount
Java中使用HttpRequest調用RESTfull的DELETE方法接口提示:How to fix HTTP method DELETE doesn't support output
del spring -m blog view bugs gpo pri not 說明:無論是Spring框架還是Spring Boot的Feign形式的客戶端,以下的解決方法都適用。 解決方法:直接升級JDK 1.8,這個問題是1.7的BUG。 參考: htt
How to add and delete users on an Ubuntu 16.04?
How to add and delete users on an Ubuntu 16.04? https://www.digitalocean.com/community/tutorials Introduction One of the most basic tasks to
How to forcefully delete a daemonset or a pod in kubernetes cluster
I have setup a kubernetes cluster which is working fine. I created deployment with type as daemonset which then created few p
Ubuntu 添加刪除用戶 How to Add and Delete Users on Ubuntu 16.04
spa problem del sig event cau hand perf tell Introduction One of the most basic tasks that you should know how to do on a fresh Linux
Centos/RHEL :How to add,delete and display LVM tags
1. 什麼是LVM標籤? 在你想開機啟動時讓邏輯卷被啟用可用時,新增lvm標籤是一個不錯的選擇。lvm標籤允許那些被預先標記的實現這樣的效果。 2. 配置檔案 配置檔案/etc/lvm/lvm.conf中有這樣一段話: # vim /etc/lvm/lvm.conf # If v
How to find a Process Listening on a Specific Port in Linux? netstat and lsof command examples
In Linux, many times, you want to find out the PID of a process which is listening on a port e.g. if multiple tomcat servers are running on a host and you
Ubuntu 新增刪除使用者 How to Add and Delete Users on Ubuntu 16.04
Introduction One of the most basic tasks that you should know how to do on a fresh Linux server is add and remove users. When you create a new system, y
How to Correctly Store App-Specific Files in Android
Christophe Versieux (Waza_be) posted a rant about android developers' bad habit to store files directly on the root o
How to make Git preserve specific files while merging
How to make Git preserve specific files while mergingOh boy, are branches great. They let you have entirely different versions of a given file, depending o
How to downgrade HWM for a specific tablespace
--This scripts is used to handle HWM for a tablespace--Run this script to get the target script named HandleHWM_TargetScripts.sqlset echo
窩上課不聽,how to learn C language easily(1)
程序 簡單 小數 如果 如何 好處 class 數組 指針 C language 學習心得 附:為啥起這麽霸氣側漏,招大神們鄙視的標題,正如我在《C language》隨筆的介紹中寫的,這是一個寫個妹紙們看的C language的文章。沒錯!!寫這篇文章的靈感也來自於上周C
<轉>How to Encourage Your Child's Interest in Science and Tech
sim challenge table nic options https fun developed advice How to Encourage Your Child‘s Interest in Science and Tech This week’s Ask-A-D
Livemedia-creator- How to create and use a Live CD
download further burning method create Livemedia-creator- How to create and use a Live CDNote for older method (namely for Fedora 23) using livec
How to search Installed Updates
windows 控制 asp blank list ren nag earch txt Windows本身的控制面板中自帶的搜索,無法根據補丁編號進行搜索 可以將補丁信息導出到文本,再用文本編輯器進行查找 https://www.concurrency.com/blog
How to fix yum errors on CentOS, RHEL or Fedora
http dsm list plain ... prop package cat cse Yum is a package management tool for installing, updating and removing rpm packages on Red