PudgyDragon Knowledge Base

Guides

Installation, implementation, hardening, integration, and operational guidance organized by project.

Corelight · Engineering GuideCorelight Proxy Configuration

Configure a Corelight Software Sensor to operate behind an enterprise proxy.

Corelight · Engineering GuideCorelight Fleet Manager Deployment

Deploy Corelight Fleet Manager on Proxmox Virtual Environment.

Corelight · Engineering GuideProxmox Host Configuration

Configure a Proxmox VE host to support Corelight virtual appliances.

Corelight · Engineering GuideCorelight Sensor Deployment

Deploy a Corelight Software Sensor on Proxmox Virtual Environment.

Gigamon · Engineering GuideGigamon FM IP Configuration

Change the management IP address of Gigamon Fabric Manager.

Gigamon · Engineering GuideGigamon TLS Certificate Installation

Install and configure TLS certificates for Gigamon Fabric Manager and Nodes.

Gigamon · Engineering GuideGigamon Upgrade Guide

Upgrade Gigamon Fabric Manager and GigaVUE appliances to a newer software release.

Gigamon · Engineering GuideGigamon Command Reference

Reference commonly used CLI commands for administering and troubleshooting Gigamon appliances.

Gigamon · TroubleshootingGigamon RADIUS Troubleshooting

Troubleshoot RADIUS authentication issues in Gigamon.

MISP · Threat IntelligenceMISP AWS Deployment

Deploy the Malware Information Sharing Platform (MISP) on Amazon Web Services.

MISP · Threat IntelligenceMISP Container Deployment

Deploy the Malware Information Sharing Platform (MISP) using Docker containers.

OpenCTI · Threat IntelligenceAlienVault Integration

Configure the AlienVault connector for OpenCTI.

OpenCTI · Threat IntelligenceOpenCTI CISA KEV Integration

Configure the CISA Known Exploited Vulnerabilities (KEV) connector for OpenCTI.

OpenCTI · Threat IntelligenceOpenCTI MISP Integration

Configure the MISP connector for OpenCTI.

OpenCTI · Threat IntelligenceOpenCTI RSS Feed Reference

Reference RSS feeds that have been verified to work with OpenCTI.

OpenCTI · Threat IntelligenceOpenCTI Installation Guide

Install and configure OpenCTI for threat intelligence management.

QRadar · Engineering GuideQRadar Data Node Associations

Associate data nodes with a QRadar Console or Event Processor.

QRadar · Engineering GuideQRadar Watson Investigation Cleanup

Delete Watson investigations from QRadar using the command line.

QRadar · Engineering GuideQRadar Email Server Configuration

Configure an SMTP email server for QRadar notifications and alerts.

QRadar · Engineering GuideQRadar FIPS Configuration

Enable FIPS mode on QRadar appliances running Red Hat Enterprise Linux 8.

QRadar · Engineering GuideConfigure an HA Crossover Cable

Configure and verify a dedicated crossover interface for IBM QRadar High Availability (HA) pairs.

QRadar · Engineering GuideExport and Import QRadar Content Packages

Export and import custom QRadar content, including reports, DSMs, rules, and reference data, using the Content Management Tool.

QRadar · Engineering GuideDeploy IBM QRadar SIEM on Red Hat Enterprise Linux 8 (Current Guide)

Deploy IBM QRadar SIEM 7.5 on Red Hat Enterprise Linux 8 using enterprise storage layouts for Console, Application Host, Event Processor, Flow Processor, High Availability, and QRadar Network Insights appliances.

QRadar · Engineering GuideDeploy Legacy IBM QRadar on Red Hat Enterprise Linux (SSD/HDD Storage)

Deploy legacy IBM QRadar releases on customer-provided hardware using separate SSD operating system storage and HDD data storage. For newer deployments, refer to the RHEL 8 installation guide.

QRadar · Engineering GuideInstall an IBM QRadar Interim Fix

Install an IBM QRadar Interim Fix (IF) by mounting the update package, applying the installer, and verifying the installed version across all managed hosts.

QRadar · Engineering GuideRecover a Lost Root Password

Recover a lost root password on IBM QRadar by booting into the RHEL emergency environment and resetting the password.

QRadar · Engineering GuideConfigure QRadar Routing Rules

Configure QRadar routing rules to drop events, bypass the Custom Rules Engine (CRE), or forward events for log storage while managing event processing and licensing.

QRadar · STIGImplement DISA STIGs on IBM QRadar

Apply the DISA RHEL 8 and Central Syslog Server STIGs to IBM QRadar using field-tested implementation guidance and QRadar-specific exceptions.

QRadar · STIGLegacy IBM QRadar STIG Implementation Guide

Legacy STIG implementation procedures for IBM QRadar 7.5.0 Update 6. Preserved for historical reference and not intended for newer QRadar releases.

QRadar · Engineering GuideUpgrade IBM QRadar to Update Package 8 (RHEL 8)

Upgrade IBM QRadar 7.5 Update Package 7 to Update Package 8, including the RHEL 8 migration, prerequisite validation, troubleshooting, and post-upgrade verification.

QRadar · TroubleshootingResolve Application Errors When Grouping Searches

Resolve QRadar application errors caused by duplicate custom event property names that conflict with built-in event properties.

QRadar · TroubleshootingResolve QRadar Apps Missing from the Dashboard

Restore IBM QRadar applications that are missing from the dashboard by restarting app instances with the qappmanager support utility.

QRadar · TroubleshootingDelete Stuck Watson Investigations Using the API

Delete IBM QRadar Watson investigations that cannot be removed through the user interface by using the built-in REST API.

QRadar · TroubleshootingResolve Cisco ISE pxGrid Configuration Errors

Resolve Cisco ISE pxGrid application configuration errors caused by stale browser data when configuring the QRadar Cisco ISE pxGrid application.

QRadar · TroubleshootingResolve QRadar Core Services That Fail to Start After an Upgrade

Resolve IBM QRadar core services that fail to start after an upgrade due to disk utilization exceeding the supported threshold.

QRadar · TroubleshootingResolve Docker Applications Blocked by Trellix or McAfee Agent

Resolve QRadar application issues caused by unsupported Trellix or McAfee Endpoint Security agents installed on QRadar appliances.

QRadar · TroubleshootingTroubleshoot QRadar Email Delivery Issues

Troubleshoot IBM QRadar email notifications by verifying Postfix configuration, testing email delivery, and reviewing mail logs.

QRadar · TroubleshootingResolve 'Failed to Locate the SFS Patch File' During an Update

Resolve the 'Failed to locate the SFS patch file' error by removing stale mounts from the QRadar update directory.

QRadar · TroubleshootingUpdate Package 8 Interim Fix 3 Installation Issue

Resolve a patch-sensitive issue encountered while installing IBM QRadar 7.5 Update Package 8 Interim Fix 3.

QRadar · TroubleshootingUpdate Package 7 Interim Fix 6 Deployment Issues

Resolve deployment failures encountered while installing IBM QRadar 7.5 Update Package 7 Interim Fix 6.

QRadar · TroubleshootingResolve Ariel IO Errors During Searches

Resolve QRadar Ariel search IO errors caused by failed SSH tunnels between the Console and managed Event Processors or Data Nodes.

QRadar · TroubleshootingResolve LDAP SSL Certificate Errors During User Analytics Imports

Resolve SSL certificate validation errors encountered during QRadar User Analytics LDAP imports by updating trusted certificates and verifying LDAP server configuration.

QRadar · TroubleshootingResolve Stuck Application Install or Uninstall Tasks

Resolve the QRadar error 'another preview/install/uninstall task is currently in process' by clearing stale application installation records.

QRadar · TroubleshootingResolve Failed Yum Transaction Test During QRadar Version Upgrades (RHEL 7)

Resolve failed yum transaction test errors encountered during QRadar version upgrades on RHEL 7 appliances.

Security Analytics · Engineering GuideCLI Command Reference - Monitoring & Diagnostics

Monitoring, health, and diagnostic commands for Broadcom Security Analytics appliances.

Security Analytics · Engineering GuideSearch Queries

Common search queries for Broadcom Security Analytics 8.2.7.

Security Analytics · Engineering GuideRemapping the Management Interface (eth0)

Move the Security Analytics management interface to a different physical network port on custom hardware.

Security Analytics · Engineering GuideExpanding Capture Storage with an Additional Storage Array

Extend the Security Analytics capture volume after adding an additional storage array.

Security Analytics · Engineering GuideInstalling Security Analytics 8.2.6 on Dell Hardware

Installing Broadcom Security Analytics 8.2.6 on Dell hardware using the DVD ISO installation media.

Security Analytics · Engineering GuideRemoving Legacy Metadata Before Upgrading to Security Analytics 8.4.1

Remove legacy metadata that blocks upgrades to Broadcom Security Analytics 8.4.1.

Security Analytics · Engineering GuideConfiguring Smart Card Authentication

Configure LDAP and Smart Card authentication for Broadcom Security Analytics.

Security Analytics · Engineering GuideInstalling Security Analytics on Proxmox

Installing Broadcom Security Analytics as a virtual machine on Proxmox.

Security Analytics · STIGSecurity Analytics STIG Reference

Common Security Analytics settings that assist with meeting Network Device Management STIG requirements.

Security Analytics · Engineering GuideUpgrading Security Analytics

Preparing for and upgrading Broadcom Security Analytics using the official upgrade ISO.

Security Analytics · Engineering GuideVacuuming PostgreSQL Databases

Perform PostgreSQL database maintenance using vacuumdb as part of troubleshooting disk space issues on Broadcom Security Analytics.

Security Analytics · Engineering GuideRestoring Yum Repository Access

Restore yum functionality after CentOS repositories are moved to the CentOS Vault.

Security Analytics · TroubleshootingTroubleshooting Follow TCP Stream Failures

Resolve Follow TCP Stream failures caused by an unexpected duplicate /pfs directory.

Security Analytics · TroubleshootingTroubleshooting Internal Server Error Caused by Storage Layout

Resolve recurring Internal Server Error conditions caused by an incorrect storage layout on Broadcom Security Analytics.

TippingPoint · Engineering GuideChanging the SMS IP Address

Safely change the IP address of the TippingPoint Security Management System (SMS) while preserving managed devices.

TippingPoint · Engineering GuideManually Updating Digital Vaccines

Manually update Digital Vaccines and supporting threat databases on Trend Micro TippingPoint SMS.

TippingPoint · Engineering GuideUpgrading the SMS and TPS Appliances

Upgrade the Trend Micro TippingPoint Security Management System (SMS) and managed TPS appliances using manually downloaded software packages.

XSOAR · Engineering GuideAdd Custom SSL Certificate

Replace the default Cortex XSOAR SSL certificate with a custom certificate signed by your organization's Certificate Authority.

XSOAR · Engineering GuideInstall Cortex XSOAR on Red Hat Enterprise Linux

Deploy Cortex XSOAR 6.14 on Red Hat Enterprise Linux 9.6 in an on-premises environment, including STIG considerations, prerequisite configuration, and post-installation setup.