Release of QRadar 7.5.0 Update Package 5 SFS (7.5.0-QRADAR-QRSIEM-20230301133107)
Release of QRadar 7.5.0 Update Package 5 SFS (7.5.0-QRADAR-QRSIEM-20230301133107)
Release of QRadar 7.5.0 Update Package 5 SFS (7.5.0-QRADAR-QRSIEM-20230301133107)
0-QRADAR-QRSIEM-20230301133107)
Release Notes
Abstract
This technical note contains installation instructions, and a list of new features and resolved issues for the IBM
Security QRadar 7.5.0 Update Package 5 (7.5.0-QRADAR-QRSIEM-20230301133107) SFS. These instructions
are intended for administrators who are upgrading to QRadar 7.5.0 Update Package 5 by using an SFS file.
Content
What's New
For information on new and changed features in QRadar 7.5.0, see What's new in 7.5.0
(https://www.ibm.com/docs/en/qsip/7.5?topic=750-qradar).
The postgresql 11 precheck is independent of the disk space requirements that are calculated by the update
package. The update package determines the space required to upgrade the postgresql databases, as well as
other RPMs and files needed for install/upgrade/copy.
Known Issues
Important: QRadar 7.5.0 Update Package 5 contains tuning changes that can slow ecs-ec components
resulting in delays and events routing to storage as mentioned in IJ46418
(https://www.ibm.com/support/pages/apar/IJ46418). Administrators are advised to upgrade to QRadar 7.5.0
Update Package 5 Interim Fix 02
(https://www.ibm.com/support/fixcentral/swg/downloadFixes?parent=IBM%20Security&product=ibm/Other+software/IBM+Securit
y+QRadar+SIEM&release=All&platform=All&function=fixId&fixids=7.5.0-QRADAR-QRSIEM-20230503175608INT&includeRequis
ites=1&includeSupersedes=0&downloadMethod=http&source=fc)
to ensure they are not impacted.
Custom cache tuning overwritten during upgrades to QRadar 7.5.0 Update Package 5
https://www.ibm.com/support/pages/node/6959875 1/10
12/08/2024, 19:42 Release of QRadar 7.5.0 Update Package 5 SFS (7.5.0-QRADAR-QRSIEM-20230301133107)
Important: Upgrades to 7.5.0 Update Package 5 will overwrite custom cache tuning
in /opt/qradar/conf/spillovercache.properties. Before performing the upgrade, run the following command to
backup the file:
It is possible the threshold values will need to be corrected after the upgrade is completed. Contact
support for further assistance.
Upgrades to QRadar 7.5.0 Update Package 5 might take longer to complete due to glusterfs file
cleanup
Important: Upgrades to QRadar 7.5.0 Update Package 5 might take an extended amount of time to
complete due to glusterfs file cleanup. You must allow the upgrade to continue uninterrupted.
After upgrading to QRadar 7.5.0 Update Package 5, WinCollect 7.X agents can experience
management or configuration change errors
Important: A flash notice exists for this issue. For the latest information,
see https://www.ibm.com/support/pages/node/6953887 (https://www.ibm.com/support/pages/node/6953887).
After you upgrade to QRadar 7.5.0 or later, type the following command to check your autoupdate
version:
/opt/qradar/bin/UpdateConfs.pl -v
Review the issue and the resolution section for your auto update version on the following technical
note, https://www.ibm.com/support/pages/node/6515880 (https://www.ibm.com/support/pages/node/6515880).
Docker services do not start when 7.2.8 or earlier appliances are updated to 7.5.0 Update
Package 2 Interim Fix 02 or 7.5.0 Update Package 3
Docker services fail to start on QRadar appliances that were originally installed at version 7.2.8 or
earlier, then upgraded to 7.5.0 Update Package 2 Interim Fix 02 or 7.5.0 Update Package 3.
Before you upgrade to QRadar 7.5.0 Update Package 2 Interim Fix 02 run the following command from
the QRadar Console:
Review the output to confirm the ftype setting. If the output setting displays "ftype=0", do not proceed
with the upgrade to 7.5.0 Update Package 2 Interim Fix 02 or 7.5.0 Update Package 3.
Kernel crash can affect UEFI systems in QRadar 7.4.0 Fix Pack 3 through to QRadar 7.4.3 Fix
Pack 2.
If you are planning to upgrade from any version of QRadar 7.4.0 Fix Pack 3 through to QRadar 7.4.3 Fix
Pack 2, contact support.
For more information, see IJ44385 (https://www.ibm.com/support/pages/apar/IJ44385).
https://www.ibm.com/support/pages/node/6959875 2/10
12/08/2024, 19:42 Release of QRadar 7.5.0 Update Package 5 SFS (7.5.0-QRADAR-QRSIEM-20230301133107)
Resolved Issues
For a list of APAR links of resolved issues in QRadar 7.5.0 Update Package 5, see Authorized Program
Analysis Reports (https://www.ibm.com/community/qradar/support/apars/).
Some APAR links might take 24 hours to display properly after a software release is posted to IBM Fix
Central.
• IJ29849 (https://www.ibm.com/support/pages/apar/IJ29849): Logging for tenant filtering only logs one tenant
and reports incorrect values.
https://www.ibm.com/support/pages/node/6959875 3/10
12/08/2024, 19:42 Release of QRadar 7.5.0 Update Package 5 SFS (7.5.0-QRADAR-QRSIEM-20230301133107)
https://www.ibm.com/support/pages/node/6959875 4/10
12/08/2024, 19:42 Release of QRadar 7.5.0 Update Package 5 SFS (7.5.0-QRADAR-QRSIEM-20230301133107)
https://www.ibm.com/support/pages/node/6959875 5/10
12/08/2024, 19:42 Release of QRadar 7.5.0 Update Package 5 SFS (7.5.0-QRADAR-QRSIEM-20230301133107)
• IBM QRadar SIEM is vulnerable to privilege escalation (CVE-2022-43863), see Security Bulletin
(https://www.ibm.com/support/pages/node/6964862).
• IBM QRadar SIEM is vulnerable to using components with known vulnerabilities, see Security
Bulletin (https://www.ibm.com/support/pages/node/6967016).
Upgrade information
QRadar 7.5.0 Update Package 5 resolves reported issues from users and administrators from previous
QRadar versions. This cumulative software update fixes known software issues in your QRadar
deployment. QRadar software updates are installed by using an SFS file, and update all appliances
attached to the QRadar Console.
https://www.ibm.com/support/pages/node/6959875 6/10
12/08/2024, 19:42 Release of QRadar 7.5.0 Update Package 5 SFS (7.5.0-QRADAR-QRSIEM-20230301133107)
• Back up your data before you begin any software upgrade. For more information about backup
and recovery, see the QRadar Administration Guide
(https://www.ibm.com/docs/en/SS42VS_7.5/pdf/b_qradar_admin_guide.pdf).
• To avoid access errors in your log file, close all open QRadar sessions.
• The QRadar software update cannot be installed on a managed host that is at a different
software version from the Console. All appliances in the deployment must be at the same
software revision to update the entire deployment.
• Verify that all changes are deployed on your appliances. The update cannot install on
appliances that have changes that are not deployed.
• If this is a new installation, review the instructions in the QRadar Installation Guide
(https://www.ibm.com/docs/en/SS42VS_7.5/pdf/b_siem_inst.pdf).
Procedure
1. Download the software update to install QRadar 7.5.0 Update Package 5 from the IBM Fix
Central website:
http://www.ibm.com/support/fixcentral/swg/quickorder?
parent=IBM%20Security&product=ibm/Other+software/IBM+Security+QRadar+SIEM&release=All
&platform=All&function=fixId&fixids=7.5.0-QRADAR-QRSIEM-
20230301133107&includeRequisites=1&includeSupersedes=0&downloadMethod=http&source=fc
(http://www.ibm.com/support/fixcentral/swg/quickorder?parent=IBM%20Security&product=ibm/Other+software/IBM+Secu
rity+QRadar+SIEM&release=All&platform=All&function=fixId&fixids=7.5.0-QRADAR-QRSIEM-20230301133107&include
Requisites=1&includeSupersedes=0&downloadMethod=http&source=fc)
3. To verify you have enough space (5GB) in /store/tmp for the QRadar Console, type the
following command:
df -h /tmp /storetmp /store/transient | tee diskchecks.txt
If the disk check command fails, retype the quotation marks from your terminal, then re-run the
command. This command returns the details to both the command window and to a file on the Console
named diskchecks.txt. Review this file to ensure that all appliances have at minimum 5GB of space
available in a directory to copy the SFS before attempting to move the file to a managed host. If
required, free up disk space on any host that fails to have less that 5GB available.
https://www.ibm.com/support/pages/node/6959875 7/10
12/08/2024, 19:42 Release of QRadar 7.5.0 Update Package 5 SFS (7.5.0-QRADAR-QRSIEM-20230301133107)
Note: In QRadar 7.3.0 and later, an update to directory structure for STIG-compliant directories reduces
the size of several partitions. This can impact moving large files to QRadar.
2. Use SCP to copy the files to the QRadar Console to the /storetmp directory or a location with
5GB of disk space.
3. Change to the directory where you copied the patch file. For example,
cd /storetmp
4. To mount the patch file to the /media/updates directory, type the following command:
mount -o loop -t squashfs /storetmp/750-QRADAR-QRSIEM-2021.6.5.20230301133107.sfs /media/up
Note: The first time that you run the software update, there might be a delay before the software
update installation menu is displayed.
• If you do not select the all option, you must select your Console appliance.
As of QRadar 7.2.6 Patch 4 and later, you are only provided the option to update all or
update the Console appliance. Managed hosts are not displayed in the installation menu to
ensure that the Console is patched first. After the Console is patched, a list of managed
hosts that can be updated is displayed in the installation menu. This change was made
starting with QRadar 7.2.6 Patch 4 to ensure that the Console appliance is always updated
before managed hosts to prevent upgrade issues.
If you want to patch systems in series, you can update the Console first, then copy the
patch to all other appliances and run the patch installer individually on each managed host.
The Console must be patched before you can run the installer on managed hosts. When
updating in parallel, there is no order required in how you update appliances after the
Console is updated.
If your Secure Shell (SSH) session is disconnected while the upgrade is in progress, the
upgrade continues. When you reopen your SSH session and rerun the installer, the patch
installation resumes.
Installation wrap-up
https://www.ibm.com/support/pages/node/6959875 8/10
12/08/2024, 19:42 Release of QRadar 7.5.0 Update Package 5 SFS (7.5.0-QRADAR-QRSIEM-20230301133107)
1. After the patch completes and you have exited the installer, type the following command:
umount /media/updates
A summary of the software update installation advises you of any managed hosts that were not
updated. If the software update fails to update a managed host, you can copy the software update to
the host and run the installation locally.
After all hosts are updated, send an email to your team to inform them that they will need to clear their
browser cache before they log in to the QRadar SIEM interface.
QRadar 101
QRadar Documentation
QRadar Training
Document Information
More support for:
IBM Security QRadar SIEM (https://www.ibm.com/mysupport/s/topic/0TO5000000025xMGAQ)
Component:
QRadar Apps
Software version:
7.5.0
Operating system(s):
Linux
Document number:
6959875
https://www.ibm.com/support/pages/node/6959875 9/10
12/08/2024, 19:42 Release of QRadar 7.5.0 Update Package 5 SFS (7.5.0-QRADAR-QRSIEM-20230301133107)
Modified date:
12 May 2023
https://www.ibm.com/support/pages/node/6959875 10/10