Digital Developer Conference: a FREE half-day online conference focused on AI & Cloud – North America: Nov 2 – India: Nov 9 – Europe: Nov 14 – Asia Nov 23 Register now

Close outline
  • United States
IBM?
  • Site map
IBM?
  • Marketplace

  • Close
    Search
  • Sign in
    • Sign in
    • Register
  • IBM Navigation
IBM Developer Answers
  • Spaces
    • Blockchain
    • IBM Cloud platform
    • Internet of Things
    • Predictive Analytics
    • Watson
    • See all spaces
  • Tags
  • Users
  • Badges
  • FAQ
  • Help
Close

Name

Community

  • Learn
  • Develop
  • Connect

Discover IBM

  • ConnectMarketplace
  • Products
  • Services
  • Industries
  • Careers
  • Partners
  • Support
10.190.13.195

Refine your search by using the following advanced search options.

Criteria Usage
Questions with keyword1 or keyword2 keyword1 keyword2
Questions with a mandatory word, e.g. keyword2 keyword1 +keyword2
Questions excluding a word, e.g. keyword2 keyword1 -keyword2
Questions with keyword(s) and a specific tag keyword1 [tag1]
Questions with keyword(s) and either of two or more specific tags keyword1 [tag1] [tag2]
To search for all posts by a user or all posts with a specific tag, start typing and choose from the suggestion list. Do not use a plus or minus sign with a tag, e.g., +[tag1].
  • Ask a question

UBA went AWAL, seem's like it got corrupted.

27000730S3 gravatar image
Question by EricLauzon  (213) | Nov 24, 2016 at 12:30 PM qradarubaextensions

What would be the possible reason for UBA to go AWAL?

Since three days, the main UBA Dashboard was working fine but when trying to inspect users, nothing was showing up, something like queries where not giving detailed activity. When replaying queries in Advanced log search that where present in the UBA log, those where not working in the activity log.

Anyhow killing the run.py (as suggested by @matthew.ouelette ) did the trick, i was just wondering if other people had the same issues or what could cause such issues.

People who like this

  0
Comment
10 |3000 characters needed characters left characters exceeded
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster

1 reply

  • Sort: 
310001NGQW gravatar image

Answer by Matthew Ouellette (IBM) (1075) | Nov 24, 2016 at 01:07 PM

Which version was this? In 1.2 we fixed some issues around how we handle the asynchronous searching. In 1.1 and before it was possible to hit some deadlock scenarios with how flask was handling the search requests. Did you have app logs from before/during you hit this error? I would be curious to see any exceptions/errors in app.log and poll.log.

Comment

People who like this

  0   Show 1   Share
10 |3000 characters needed characters left characters exceeded
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster
27000730S3 gravatar image EricLauzon (213)   Nov 24, 2016 at 02:18 PM 0
Share

1.2. Found add stuff like:

Nov 22 03:22:02 127.0.0.1 [APP_ID/1302][NOT:0000003000][ERROR] Failed to perform search: "select count() as total from events where category between 24000 and 25000 and qidname(qid)='Sense Offense Inject' last 1 hours" Nov 22 03:33:02 127.0.0.1 [APP_ID/1302][NOT:0000003000][ERROR] Failed to perform search: "select count() as total from events where category between 24000 and 25000 and senseValue is not null and not ReferenceSetContains('UBA : Trusted Usernames', username) last 1 hours" app.log:Nov 24 18:17:00 127.0.0.1 [APP_ID/1302][NOT:0000003000][ERROR] Failed to generate dashboard top panel

app.log:Nov 24 18:18:40 127.0.0.1 [APP_ID/1302][NOT:0000003000][ERROR] Failed to perform search: u'select CATEGORYNAME(category) as parent, qidname(qid) as child, sum(senseValu e) as total from events where senseValue is not null and category between 24000 and 25000 and ( username = {{XXXXXXXXXXXXXX}} ) group by parent, child last 1 hours'

bash-4.1# grep -i error poll.log 2016-11-21 03:04:14,317 [com.ibm.InsiderThreat] [ERROR] - Unable to send user score event - sendto() takes exactly 3 arguments (2 given) 2016-11-22 09:21:31,081 [com.ibm.InsiderThreat] [ERROR] - Poll QRadar reference table XXXXX failed; ..

Proxy Error

Follow this question

94 people are following this question.

Answers

Answers & comments

Related questions

Announcement: QVM Externally Hosted Scans (March 1st - power outtage) 0 Answers

Reference LDAP import not polling for the selected attributes 3 Answers

LDAP import does not populate AD properties 2 Answers

UBA/Machine Learning deployment resource utilization on dedicated app node. Multiple App nodes possible? 2 Answers

UBA and 7.2.8 P1 Upgrade 1 Answer

  • Contact
  • Privacy
  • IBM Developer Terms of use
  • Accessibility
  • Report Abuse
  • Cookie Preferences

Powered by AnswerHub

Authentication check. Please ignore.
  • Anonymous
  • Sign in
  • Create
  • Ask a question
  • Spaces
  • API Connect
  • Analytic Hybrid Cloud Core
  • Application Performance Management
  • Appsecdev
  • BPM
  • Blockchain
  • Business Transaction Intelligence
  • CAPI
  • CAPI SNAP
  • CICS
  • Cloud Analytics
  • Cloud Automation
  • Cloud Object Storage
  • Cloud marketplace
  • Collaboration
  • Content Services (ECM)
  • Continuous Testing
  • Courses
  • Customer Experience Analytics
  • DB2 LUW
  • Data and AI
  • DataPower
  • Decision Optimization
  • DevOps Build
  • DevOps Services
  • Developers IBM MX
  • Digital Commerce
  • Digital Experience
  • Finance
  • Global Entrepreneur Program
  • Hadoop
  • Hybrid Cloud Core
  • Hyper Protect
  • IBM Cloud platform
  • IBM Design
  • IBM Forms Experience Builder
  • IBM Maximo Developer
  • IBM StoredIQ
  • IBM StoredIQ-Cartridges
  • IIDR
  • ITOA
  • InformationServer
  • Integration Bus
  • Internet of Things
  • Kenexa
  • Linux on Power
  • LinuxONE
  • MDM
  • Mainframe
  • Messaging
  • Node.js
  • ODM
  • Open
  • PartnerWorld Developer Support
  • PowerAI
  • PowerVC
  • Predictive Analytics
  • Product Insights
  • PureData for Analytics
  • Push
  • QRadar App Development
  • Run Book Automation
  • Search Insights
  • Security Core
  • Storage
  • Storage Core
  • Streamsdev
  • Supply Chain Business Network
  • Supply Chain Insights
  • Swift
  • UBX Capture
  • Universal Behavior Exchange
  • UrbanCode
  • WASdev
  • WSRR
  • Watson
  • Watson Campaign Automation
  • Watson Content Hub
  • Watson Marketing Insights
  • dW Answers Help
  • dW Premium
  • developerWorks Sandbox
  • developerWorks Team
  • Watson Health
  • More
  • Tags
  • Questions
  • Users
  • Badges