Hello,
we would want to remove some specific event from Ariel DB.
During January and February some misconfiguration on customer infrastructure caused a large amount of DNS events to fill a large amount of disk on event processor; we tried to configure a specific bucket for these events which deletes them after 1 week but it does not work..probably they have already been assigned to default retention bucket.
I've seen that a tool exist to remove events from Ariel DB:
https://www.ibm.com/docs/no/qradar-common?topic=spot-removing-data-from-ariel-database
Can you clarify how to use this tool and if we need to pay attention to something before running this tool?
Thanks
Davide
#QRadar#Support#SupportMigration