nerdexam
IBM

C1000-026 · Question #23

An administrator is seeing the following system notification: 38750057 - A protocol source configuration may be stopping events from being collected. What is a valid user action to this issue?

The correct answer is D. Review the /var/log/error.log file for more information. Option D is correct because QRadar system notification 38750057 specifically directs administrators to /var/log/error.log for diagnostic details when a protocol source configuration may be blocking event collection - this is the documented log file for QRadar protocol-related…

Log Source and Network Activity Configuration

Question

An administrator is seeing the following system notification:

38750057 - A protocol source configuration may be stopping events from being collected. What is a valid user action to this issue?

Options

  • ARe-install the QRadar Console
  • BReview the /var/log/qradar.log file for more information
  • CRestart the QRadar Console
  • DReview the /var/log/error.log file for more information

How the community answered

(61 responses)
  • A
    2% (1)
  • B
    10% (6)
  • C
    7% (4)
  • D
    82% (50)

Explanation

Option D is correct because QRadar system notification 38750057 specifically directs administrators to /var/log/error.log for diagnostic details when a protocol source configuration may be blocking event collection - this is the documented log file for QRadar protocol-related errors and is the appropriate first troubleshooting step.

  • Option A (Re-install the Console) is wrong because reinstallation is a drastic, last-resort action that would cause significant downtime and is never the first response to a configuration warning.
  • Option B is wrong because /var/log/qradar.log is a general QRadar log, but 38750057 specifically points to error.log - using the wrong log file wastes time and may not contain the relevant protocol source details.
  • Option C (Restart the Console) is wrong for the same reason as A - restarting is disruptive and premature when the notification itself tells you where to look first.

Memory tip: Think "Error notification → Error log." When QRadar gives you a numbered notification about something going wrong (like events not being collected), it leads you to the error log (/var/log/error.log), not the general log. Match the severity of the message to the name of the log file.

Topics

#system notifications#protocol source#event collection#troubleshooting logs

Community Discussion

No community discussion yet for this question.

Full C1000-026 Practice