Resolved Issues
The known issues resolved in the JSA 7.5.0 Update Package 15 are listed below:
-
Hybrid DR setup flow - Remove stale references of deleted Managed Hosts and Managed Host HA prior to failover and failback.
-
Rule Version History does not update Author properly.
-
After JSA 7.5.0 Update Package 14, Flow Processor continuously logs "ERSPAN is disabled" messages, flooding qradar.log and making it unusable for operational troubleshooting.
-
Unable to assign search to groups because the 'Assign Search to Group(s)' list doesn't load.
-
Hybrid Flow : Manage host_tokens.masterlist and host.token files during restoration.
-
Hybrid Flow: After failover/failback system throwing time out in first attempt of deploy changes for paired MH on DR site.
-
"Invalid License Key" Warning on JSA UI.
-
Property name is not displayed as expected for properties used in an aql (advanced search) up 7.5.x.
-
Property name is not displayed as expected for properties used in an aql (advanced search).
-
JSA asset names might not be displayed on the assets screen or not be included in a vulnerability report after being updated.
-
HA secondary disk space issues can occur when files for older versions of ecs are not removed.
-
Dropped flow JSA system notifications only display for the console ip.
-
Disabling FIPS mode using the qradar_fips_update.sh script fails to update grub properly.
-
In high availability configurations- internet connections from JSA apps use the active host's physical IP instead of the shared virtual IP.
-
JSA: Unable to uncheck "Enable for use in Rules- Forwarding Profiles and Search Indexing" due to the incorrect dependency API call.
-
Autoupdate may fail due to long running transaction on Vulnerabilities database table.
-
Issues with CRE Event Names After Restoring Partial Configuration Backup.
-
When user select multiple CEP and try to deletes it directly deletes it without going for dependency check.
-
Asset Quick Search is not working.
-
JSA Network Insights fails to parse X.509 Common Names containing a comma followed by a space ('- ').
-
Historical correlation won't start after patching from JSA 7.5.0 Update Package 11- JSA 7.5.0 Update Package 12 and JSA 7.5.0 Update Package 13.
-
JSA Risk Manager Policy Questions Failing to Return Results Due to Missing Index in vulninstance Table.
-
Parallel Patching - "Check patching status" and "View live report" options show different results.
-
JSA Risk Manager Policy question throwing error "Question submission failed due an unexpected problem".
-
LVM warning menu should not show up on MH that is not configured with LVM.
-
JSA Risk Manager Policy question monitor 'by policy" not working as expected.
-
JSA: DSM Editor fails to map subsequent events after first mapping in JSA 7.5.0 Update Package 13.
-
JSA: Log Activity- Network Activity- and Offenses Tab table width have changed and are no longer visible in a single view after JSA 7.5.0 Update Package 11, if the screen aspect ratio is set to something other than 16:9.
-
Persistent queues will not empty on Event Collectors disconnecting from port 32005 to Event Processors.
-
Flow processor Spoofing forwarding fails with error 'Failed to retrieve MAC address for 192.xx.xx.xx.'
-
JSA Risk Manager - "Rules of Device" Window- Event Button Greyed out.
-
JSA Risk Manager - Attack Path is displayed but unreadable.
-
Risk Manager - Search on Rules fails on multiple selections.
-
JSA 7.5.0 Update Package 14 and above : Backup restoration fails on destination site due to foreign key constraint violation: fk_flowsource_lookup.
-
Index management can display zeros (0) across all columns when a large time range is chosen.
-
RSS feeds widget is no longer working.
-
Report generation fails when payload contains special characters.
-
QuickFilter not taking advantage of the Lucene index, causing slow searching.