A persistent issue with the Threat Intelligence App in the JSA deployment:The app doesn't progress past the Loading screen with the message "Downloading Security Collections from IBM X-Force Exchange".
Steps to reproduce:
Login to the JSA console WebUI.
Open the Threat Intelligence App by going to the Admin tab > Threat Intelligence App.
Observe that the app gets stuck on the loading screen with the message "Downloading Security Collections from IBM X-Force Exchange".
Also, you can see the issue if navigate to the Admin tab> QRadar Assistant.
Find the Threat Intelligence app: Threat Intelligence – QRadar v7.3.3 FP9+/7.4.1 FP2+.
The following error will be observed: "This extension is not signed properly. You can check this extension in the Extension Management UI for more details."
The app doesn't progress past the Loading screen with the message "Downloading Security Collections from IBM X-Force Exchange".Additionally, an error message is displayed in the app manager regarding the App's signature: "This extension is not signed properly. You can check this extension in the Extension Management UI for more details."
Here are our recommendations:
You need to check which authorized token is configured. Ensure it is an "admin/admin" token under Admin > Authorized Services. If it is an old one then create a new token. Creating an Authorized Service Token.
Reinstall procedure: If replacing the token does not work, please reinstall the Threat Intelligence app with the steps shared below:
Login to the JSA console or Apphost CLI, once in the CLI type the following command (/opt/qradar/support/qappmanager) and check for the <app id> of the Threat Intelligence app, under App definitions and App instances.
In JSA GUI go to the Admin tab> Extension Management > Threat Intelligence:
On the installed tab then click on the threat intelligence app.
Click on the Uninstall button.
Make sure the Threat intelligence app is no longer visible under installed apps under the Admin tab, Extension Management dialog box.
Login to the JSA console or Apphost CLI and check if the Threat intelligence app is no longer visible using (/opt/qradar/support/qappmanager | grep <app id>) utility, you must check both sections: App definitions and App instances, you shouldn't see any entries that contain Threat Intelligence.
Also, the Console/App host CLI confirms that the container has stopped running:
# docker ps | grep <app id>
You can use the Qradar assistant or login to the App exchange to download the latest version of the Threat Intelligence app.
If this doesn't work, please open a JTAC case using the following link: Contact Juniper Support