An administrator needs to collect logs from the Command Line Interface (CLI). Which command should the administrator use?
A. /opt/bin/qradar/support/get_logs.sh
B. /opt/support/get_logs.sh
C. /opt/support/qradar/get_logs.sh
D. /opt/qradar/support/get_logs.sh
An administrator is seeing the following system notification:
38750057 – A protocol source configuration may be stopping events from being collected.
What is a valid user action to this issue?
A. Re-install the QRadar Console
B. Review the /var/log/qradar.log file for more information
C. Restart the QRadar Console
D. Review the /var/log/error.log file for more information
An administrator may be asked to collect diagnostic information on one of our main services. For example, ecs-ec.
Commands such as: /opt/qradar/support/thredtop.sh /opt/qradar/support/jmx.sh
These commands collect thread and statistical information on the Services pipeline, queues and filters.
How would an administrator identify a list of jmx ports for each service?
A. grep JMXPORT /opt/qradar/init/*
B. grep JMXPORT /opt/qradar/systemd/env/*
C. grep JMXPORT /opt/qradar/system/bin/*
D. grep JMXPORT /opt/qradar/system/mem/*
An administrator needs to complete the upgrade process from V7.3.1 to V7.3.2. What is the correct procedure?
A. Copy the ISO file extension to the recommended directories and use this file
B. Use the ISO file to execute the upgrade process
C. Do a clean installation using the ISO file on a bootable USB device
D. Copy the SFS file extension to the recommended directories and use this file
An administrator has reviewed the list of new features in the QRadar V7.3.2 release notes, and decides to upgrade their system to this version.
What is the minimum supported version that the administrator can upgrade from?
A. 7.2.6
B. 7.3.0
C. 7.3.1
D. 7.2.8
When an administrator attempts to edit a log source after upgrading QRadar, a Device Support Module (DSM), a protocol, or Vulnerability Information Services (VIS) components, the following error message appears.
An error has occurred. Refresh your browser (press F5) and attempt the action again. If the problem persists, please contact customer support for assistance.
What action should the administrator take to troubleshoot this issue? (Choose two.)
A. systemctl restart snmpd
B. systemctl restart iptables
C. systemctl restart ecs-ep
D. systemctl start tomcat
E. systemctl restart httpd
F. Clear browser cache
An administrator needs to save a search to use it in the dashboards.
To do so, which search feature does the administrator need to select in the "Include in my Dashboard" checkbox?
A. Filter events of the last 7 days
B. Filter events of the last month
C. Filter events of the last 5 minutes
D. Group by some property
An administrator installed a new App Host and would like to move the existing applications from the Console to the App Host.
What steps should be performed?
A. Admin Tab > Extension Management > Click to change where apps are run
B. Admin Tab > System Settings > Move apps
C. Admin Tab > Extension Management > Move apps
D. Admin Tab > System and License Management > Click to change where apps are run