Helpful Integration Notes
- QRadar log activity does not differentiate between different installs of the extension. All log events go into the same log file. As a result the log might include events from previous installs without any impact.
- You should not select "preserve existing items" during the install. This option is not supported for Lookout Integration.
- Changes to the Lookout Integration configuration can take up to 2 minutes to take effect due to the timing constraints of the internal event runner.
- Changing any application properties related to retrieving events does not reset the "Total Events Fetched" counter. This is a lifetime total counter from the time the integration was first installed and configured.
- The extension retrieves events from Lookout every 30 seconds.
- When uninstalling, the "...not supported" warnings for skip, revert, and uninstall are expected behavior due to QRadar’s internal processes.