Activation
Which capabilities need a licence, how to get a trial, online and offline activation, licence states, upgrade notes.
The generic flow (online / offline, deactivation, common errors) is under Platform → Licence activation; this page covers what is specific to QRadar AI Copilot. "Activation" sits in the tabs of Settings, administrators only.
What needs a licence
| Tier | What you get |
|---|---|
| Unactivated | Ask AI, offense sync and dispositions, all masking modes, posture / audit / reports / platform checks, under a daily LLM quota (200 by default) |
| Trial | = Standard for 14 days, one host. Apply in the console |
| Standard / Enterprise | The four paid engines: offense batch triage, offense investigation, rule copilot, platform-ops copilot (the AI read on Platform health) |
The four paid engines ship encrypted: the image carries only ciphertext, and the licence server issues each key per tier, bound to the activated host. A gateway without a licence cannot run them.
Overview
| Card | Meaning |
|---|---|
| Licence state | See the table below |
| Expiry | Days left; "renew soon" within 30 days |
| Unlocked features | Listed per feature, or "wildcard * (Enterprise)" |
| Usage | Today's quota when unactivated; "unlimited" once activated; last heartbeat |
States
| State | Meaning | Do |
|---|---|---|
| Unactivated | No licence; free features under quota | Apply for a trial or buy |
| Valid | Normal | — |
| Expiring | Within 30 days of expiry | Renew, paste the new key |
| Grace period | Online licence cannot reach the licence server but is inside the offline grace | Check outbound access to license.reallysec.com:443 |
| Heartbeat lost | Grace nearly used up | Same; expires automatically after the grace period |
| Expired / revoked / invalid | Paid engines locked | Contact sales; invalid usually means the key belongs to another host |
An invalid licence does not block login, logout, password change or deactivation.
Online activation
Paste the token from the console (starts with ey…) and click Activate. The gateway binds this host with the licence server and heartbeats every 5 minutes; renewals, tier changes and keys for new engines arrive over the heartbeat. The host fingerprint never has to be sent to anyone.
Offline activation
Air-gapped: copy the host fingerprint (64 hex characters), send it to Reallysec, and upload the returned .lic file (or paste its contents). Signature and fingerprint are verified locally; no heartbeat, nothing leaves the network. An offline licence's feature set is fixed in the file; renewals and tier changes need a re-issued one.
The fingerprint is derived from state/machine-id and state/server_guid in the install directory. Never regenerate them; back up the whole state/ directory.
Replace or renew / deactivate
- Replace or renew: paste the new key and activate; no need to deactivate first.
- Deactivate: back to unactivated; an online licence returns its host seat to the server. Do this before moving to another host.
AI settings
Which models to use, failover order, reasoning effort; each provider's health and 24-hour call volume.
Audit log
A record of every query, model call, offense write-back and settings change: who, when, which source, what, outcome, token usage. Filter, export, forward (QRadar itself included).