This has been a confusing topic for me (and I think many others as well).
My understanding is that events get dropped when the ecs or maybe ecs-ingress process is overwhelmed and the queue of events fills up (shows as queue 100% full) in the logged event).
My current understanding is that events that cannot be processed due to licensing restrictions are held in the queue and if the license is not maxed out in the next second, they are processed then.
When the queue is showing 100% full I have been told two things, one that events then are truly dropped, and secondly that the events can still be processed if your licensing "give back" is available. This can be seen in the QDI app. When I see the message you saw, I check in QDI on the graph for Event License give back where dropped events are tracked. I have never seen this graph show any dropped events. I do not know how to search for genuinely dropped events using Ariel.
Maybe an IBM person could chime in with a really,
really clear explanation of this for us, and include a search to check for genuinely dropped events and for a way to find out why they are dropped. Exxplain how we can figure out if it is licensing restrictions causing the event, or a physical overflow of the hardware or just overwhelming the software.
That would be great.
------------------------------
_____________________
Daniel Sichel
------------------------------
Original Message:
Sent: Tue October 15, 2019 10:15 AM
From: Pranav Sankar
Subject: QDI - 1+Billion Dropped Events
Hello All,
I'm new to QRadar SIEM Tool. In my QRadar Deployment Intelligence I'm getting a message like "A Total of 1+Billion dropped raw events are detected. 4000+raw events are dropped in last 60 seconds.License Restrictions have been applied 59 times in last 60 seconds.
What does this messages means whether 1+ billion of events is a total number of dropped events since QRadar was installed, actual drops from QTS were 4000 events+ ?
Need expertise here.
I've gone through the QRadar Troubleshooting System Notifications guide and they insisting me to reduce the volume of events. But before do so I need to know what this error means.
Much Appreciated!! Thanks
Pranav
------------------------------
Pranav Sankar
------------------------------