If it's not the case you probably are under a bug and should open a support case for that.
Original Message:
Sent: Thu August 08, 2024 11:15 AM
From: Stefano Pasa
Subject: EPS consumption
Hi Karl
I try to explain with an example:
lets assume that I have and environment with a console and an EP, 2000EPS of total license splitted half and a half between the two hosts (1000 on console and 1000 on EP)
ecs-ec-ingress on console is receiving 1500EPS and 500EPS are dropped by RR -> 1000EPS are processed and no license issues
ecs-ec-ingress on EP is receiving 1500EPS and 500EPS are dropped by RR -> here license will drop 500EPS at ecs-ec-ingress level and then remaining events are processed by ecs-ec/RR/ecs-ep
I've seen this behaviour in many environments we are managing (all on 7.5 > up3 and < up8) and I'm still troubleshooting this
------------------------------
Stefano Pasa
Original Message:
Sent: Fri July 26, 2024 09:22 AM
From: Karl Jaeger
Subject: EPS consumption
Stefano,
thats an interesting information for distributed environments. Of course processes should work the same regardless if EC and EP are distributed or not. License and routing rules process are the first services processing events o any machine as you know . Can you please explain what exactly goes wrong in your scenario? do you mean events get dropped by a drop event rule when processed on console only but not when being processed somewhere else? In the above example a drop rule might be executed anywhere regardless if EC is located on console or not. If this is not the case please open a support ticket with IBM
BTW from my experience the datastore license is not technically enforced in older releases, 750 i have not tested yet
------------------------------
[Karl] [Jaeger] [#ibmchampion]
[QRadar Specialist]
[cnag]
[Siegen] [Germany]
Original Message:
Sent: Tue July 23, 2024 03:40 AM
From: Stefano Pasa
Subject: EPS consumption
Hi
Little addition, from what I noticed this is really working only if events are processed by a console, e.g.events received by console itself or EC connected to the console and not when events are processed by an Event Processor.
I mean routing rules are applied also with Event Processor but events are dropped once raw data reach EPS assigned to that EP, this is not happening when events are processed by a Console
------------------------------
Stefano Pasa
Original Message:
Sent: Mon July 22, 2024 10:29 AM
From: Karl Jaeger
Subject: EPS consumption
Benjamin
what you need is a new routing rule in admin tab. Screenshot is showing sample. pls checkup documentation on this cause there are many variants. For your usecase you need a datastore license which will just enable writing it to storage rahter than process the selected events.
------------------------------
[Karl] [Jaeger] [#ibmchampion]
[QRadar Specialist]
[cnag]
[Siegen] [Germany]
Original Message:
Sent: Mon July 22, 2024 08:54 AM
From: Benjamin Yabre
Subject: EPS consumption
Hello,
I have a challenge with my EPS consumption and I would like to know if it's possible for Qradar to no process a certain log and transfer it straight to the storage, and what would be the impact of doing that ?
Thanks
------------------------------
Benjamin Yabre
------------------------------