Sean Hogan
2017-05-08 19:31:20 UTC
Hello IPA,
I am trying to set up User Behavioral analytics from Qradar to IPA.
Having some issues with it after we got 389 and 636 open between the nets.
Qradar Console is not in IPA and on differ net although we do have comms on
389 and 636 now
ipa-server-3.0.0-50.el6.1.x86_64
I set up an account in IPA with no HBACS or anything and just gave it a IPA
role to read data which we use in the below config.
Getting
file:///home/schogan/Documents/SametimeTranscripts/[multi-way]/20170508-100730%7BJUSTIN%20L.%20BAUMAN's%20group%20chat%7D/IMAGE
$1CFC0CDDB6F2F123.jpg
URL I have them using ldaps://IPofIPAserver.example.com
BaseDN dc=example,dc=local
filter users,cn=accounts,$Suffix
attributes are left default
username is the user i made in ipa
pw is the pw I made in ipa
file:///home/schogan/Documents/SametimeTranscripts/[multi-way]/20170508-100730%7BJUSTIN%20L.%20BAUMAN's%20group%20chat%7D/IMAGE
$1B778A1810D34E76.jpg
Has anyone attempted this or have any sample configs to play with or see
anything I am doing incorrect?
Sean Hogan
I am trying to set up User Behavioral analytics from Qradar to IPA.
Having some issues with it after we got 389 and 636 open between the nets.
Qradar Console is not in IPA and on differ net although we do have comms on
389 and 636 now
ipa-server-3.0.0-50.el6.1.x86_64
I set up an account in IPA with no HBACS or anything and just gave it a IPA
role to read data which we use in the below config.
Getting
file:///home/schogan/Documents/SametimeTranscripts/[multi-way]/20170508-100730%7BJUSTIN%20L.%20BAUMAN's%20group%20chat%7D/IMAGE
$1CFC0CDDB6F2F123.jpg
URL I have them using ldaps://IPofIPAserver.example.com
BaseDN dc=example,dc=local
filter users,cn=accounts,$Suffix
attributes are left default
username is the user i made in ipa
pw is the pw I made in ipa
file:///home/schogan/Documents/SametimeTranscripts/[multi-way]/20170508-100730%7BJUSTIN%20L.%20BAUMAN's%20group%20chat%7D/IMAGE
$1B778A1810D34E76.jpg
Has anyone attempted this or have any sample configs to play with or see
anything I am doing incorrect?
Sean Hogan