Thanks Support Member,
It is less ambiguous for me now.
However, when i try to do the math with those values i get lost again.
Example of values from the system logs in minute X:
SourceMonitor (60s) = 5821
StatFilter (60s) = 1855
Giveback = 1367
EPS for external log sources in minute X = 1809
Now, I would say that the "accurate" EPS is the one from StatFilter.
but, the sum of StatFilter and the Giveback is way less than the SourceMonitor (3222 <<< 5821 ) I wonder where the 2599 EPS are?
Thanks again.
Salma
#QRadar#Support#SupportMigration