Hi Aub.
Scenario1:
My assumptions:
- One Console (AIO without HA)
- DN1 and DN2 are in HA.
with the assumptions above, if DN1 (Primary Active data node) is down, the DN2 will take will become the secondary active and there will not by any data loss. Once the Primary DN1 is restored, and make a active again, DN2 will replicate all the interim data to DN1 from the point DN2 took over as the active node.
Scenario2:
This may have multiple sub-cases.
My assumptions:
@ SiteA the console is Primary-Active, DN1 is primary-Active and DN2 is secondary-satandby.
@ SiteB the console is Secondary-Standby, DN3 is primary-Active and DN4 is secondary-standby.
Now as per your question, if both DN(s) at siteB (DN3, and DN4) go down, then there will be no data loss, because these DN(s) are connected to secondary-Standby Console, that doesn't have the /store partition. All the data is being stored at Console's Primary-Active node and its associated DN(s), i.e. DN1 and DN2.
Now if, @ SiteA, the Primary-Active Console is down, the Secondary node @ SiteB, will become Active and still in this scenario, the DN1 and DN2 will still be storing the data, as they are communicating with the Virtual IP of Console.
Another Scenario @ SiteA, would be, that the Primary-Active Console is up and running, and DN1 gets down, then in this case, DN2 will become active and this becomes exactly the scenario number 1, mentioned above.
Another Scenario @ SiteA would be, that Primary-Active Console is up and running, and DN2, gets down, then in this case nothing will happen, because the Primary-Active DN, the DN1 is still there and keep storing the data.
When DN3 and DN4 will come into action:
DN3 and DN4 will come into action, only when SiteA console is down along with DN1 and DN2. Then in this scenario, the Secondary Console will become active and the DN3 will be working as the Primary-Active DN at this time.
But now if SiteA is restored, and the console is made active along with the DN1 and DN2, then the data at Secondary-console's internal storage, will be replicated to SiteA console. But I am not sure what will happen with DN3 and DN4 interim data. Will it be replicated to DN1 or DN2. This needs to be tested in the lab.
BR,
MBF
------------------------------
Muhammad Burhan Faruqi
------------------------------
Original Message:
Sent: Sun December 07, 2025 11:53 AM
From: Abu Mussa Elahi
Subject: Data Node Accessibility During Down Time.
Hello Community,
I would like to clarify how data accessibility works in QRadar Data Node environments.
Scenario 1:
We currently have one Console and two Data Nodes (DN1 and DN2). If one Data Node goes down (for example, DN1), will the data stored on that Data Node remain accessible during the downtime?
Scenario 2:
We are planning a two-site setup similar to an HA design:
Both sites are connected through an extended VLAN, and all 4 Data Nodes are linked to the Primary Console.
My question is:
If both Data Nodes in Site B go down, will the data that was previously stored on those Site B Data Nodes still be accessible? Or will that data remain inaccessible until the nodes come back online?
------------------------------
Abu Mussa Elahi
------------------------------