IBM Security QRadar

 View Only
Expand all | Collapse all

QRadar /store disk expansion

  • 1.  QRadar /store disk expansion

    Posted Tue April 09, 2024 07:42 PM

    Hello,

    I have a QRadar setup with Master Console, AppHost, couple of EPs running the 7.5 version of the code. On the Event Processor, the disk is running out of space for the /store partition.  This is deployed on a VMware environment.

    Could someone please let me know the procedure to increase the disk partition by attaching another disk?

    Regards,

    Umamaheshwar



    ------------------------------
    Umamaheshwara Manekar
    ------------------------------


  • 2.  RE: QRadar /store disk expansion

    Posted Wed April 10, 2024 02:18 AM

    I suppose the standard LVM extension method still not officially supported by IBM, however this is the standard method for QROC (Qradar On Cloud) and it is working perfectly. So, just google 'Extend LVM' and you'll find the solution at many sites. I have a document somewhere with all the steps required to extend /store by adding new disks, if I'll find it and noone else posting something similar I'll add it here, but again, this is just a Linux, so use standard tools



    ------------------------------
    László Pál
    ------------------------------



  • 3.  RE: QRadar /store disk expansion

    Posted Wed April 10, 2024 07:11 AM

    Hi

    The use of LVM to resize a disk in QRadara is not supported.  This can lead to data loss.

    https://www.ibm.com/support/pages/does-qradar-support-lvm-file-system-storage-expansion

    The methods listed in the above link should be used if additonal space is required

    Thanks



    ------------------------------
    John Dawson
    Qradar Support Architect
    IBM
    ------------------------------



  • 4.  RE: QRadar /store disk expansion

    Posted Wed April 10, 2024 09:12 AM

    As I said it is not 'officialy' supported, however this is the 'official method' for QROC which is basically the same as on-premise. Also we used this method for years and we never experienced any data loss

     

    L:

     

    Unless stated otherwise above:
    Kyndryl Hungary Korlátolt Felelősségű Társaság / Kyndryl Hungary Llc
    8000 Székesfehérvár, Berényi út 72-100. 35. ép
    Cg.07-09-031714 - registering court: Székesfehérvári Törvényszék Cégbírósága





  • 5.  RE: QRadar /store disk expansion

    Posted Wed April 10, 2024 09:18 AM

    QRoC add datanodes when space is required.  



    ------------------------------
    John Dawson
    Qradar Support Architect
    IBM
    ------------------------------



  • 6.  RE: QRadar /store disk expansion

    Posted Wed April 10, 2024 09:25 AM

    I see. So what do you think what is the proper solution migrating 40+ TB data from a HW appliance to a VA environment if the ESX guys screaming due to huge disks? I asked this also from support, but I'm always checking community experience as well 😊

     

    Thank you

    L:

    Unless stated otherwise above:
    Kyndryl Hungary Korlátolt Felelősségű Társaság / Kyndryl Hungary Llc
    8000 Székesfehérvár, Berényi út 72-100. 35. ép
    Cg.07-09-031714 - registering court: Székesfehérvári Törvényszék Cégbírósága





  • 7.  RE: QRadar /store disk expansion

    Posted Thu April 11, 2024 03:02 AM

    Hello , there's an long-running RFE filed on the ideas-portal which does describe the need for LVM-support: https://ibmsecurity.ideas.ibm.com/ideas/SIEMCORE-I-3299

    Please have a look at it an vote for it. Thx



    ------------------------------
    Kammerstetter Bernhard
    IBM
    (431) 211-4533 x92
    ------------------------------



  • 8.  RE: QRadar /store disk expansion

    Posted Thu April 11, 2024 03:59 AM

    Not directly the answer to this question, but the easiest way is adding the Data node. 

    As the LVM method is not officially supported, what I did few times (to steer away from other trouble) is: provision a new (properly sized) virtual disk, add it to the QRadar instance and (after discovering the new disk) proceeded with migrating the /store to the new "disk"; for the last part you can follow the steps from the Offboard storage guide. 



    ------------------------------
    Dusan VIDOVIC
    ------------------------------



  • 9.  RE: QRadar /store disk expansion

    Posted Thu April 11, 2024 07:53 AM

     

     

    Yeah, but what if we have to use smaller disks due to ESX and we still have to migrate 40TB of data from the old M4 HW to the SW environment?

     

    L:

    Unless stated otherwise above:
    Kyndryl Hungary Korlátolt Felelősségű Társaság / Kyndryl Hungary Llc
    8000 Székesfehérvár, Berényi út 72-100. 35. ép
    Cg.07-09-031714 - registering court: Székesfehérvári Törvényszék Cégbírósága





  • 10.  RE: QRadar /store disk expansion

    Posted Thu April 11, 2024 08:05 AM

    Then you would create a new Virtual Machine with the disk size required

    https://www.ibm.com/docs/en/qsip/7.5?topic=installations-installing-rhel-your-system

    Then you would follow the HW migration procedure

    https://www.ibm.com/docs/en/qsip/7.5?topic=hardware-qradar-siem-migration-scenarios

    To clarify LVM is used in QRadar but the resizing of disks once in production is not supported in QRadar and may cause data loss and would result in an unsupported device



    ------------------------------
    John Dawson
    Qradar Support Architect
    IBM
    ------------------------------



  • 11.  RE: QRadar /store disk expansion

    Posted Fri April 12, 2024 06:32 PM

    Thank you @John Dawson for your response. What do you mean by an unsupported device?



    ------------------------------
    Umamaheshwara Manekar
    ------------------------------



  • 12.  RE: QRadar /store disk expansion

    Posted Sat April 13, 2024 02:24 AM
    Hi

    Here is the full answer from IBM closing this issue

    Hi László,

     

    My name is Stephen and I am one of Michael's team leads.

     

    We have received your escalation "It seems the assigned engineer does not understand my two simple questions"

     

    I have reviewed the case and believe the simple questions are and please see answer's

     

     

    "Several ppl. -including me- states it is only a documentation issue and never experienced data loss due to extending /store using standard LVM tools, so why exactly it is not officially supported?!

     

    "What do you mean 'unsupported'? It means if we extend /store using LVM, IBM will refuse helping in case we are opening a ticket? That is very strange because we used the same extend method in my previous position for years -I suppose I'm not the only one-, and IBM never refused helping us in this case"

     

    I will answer these two questions as there is some overlap . 

     

    I cannot comment on your previous position or help you were given, but our documentation clearly states this is unsupported.

     

    https://www.ibm.com/support/pages/does-qradar-support-lvm-file-system-storage-expansion

     

    It is not officially supported because "Currently, expanding LVM in QRadar is an untested process and not supported. LVM expansion can cause data loss, system failures, or put a system into an unrecoverable state, which could require the rebuilding of your deployment."

     

    What this means is that if you do expand it and it causes issues, you will be told to rebuild. This does not mean you will be refused to log a case, just that if you do raise a case and it is identified that this is the cause of your issues you will be told to rebuild. 

     

     

    "What is the official suggestion from IBM in our scenario when we have to migrate 40TB of data from EOL HW Appliance to SW Appliance and the Virtualisation team does not willing to allocate a single 40TB disk because it is not recommended by virtualisation vendor (vmware)?"

     

    Michael has provided a solution to this

     

    You would need to carry out a RH install utilising say 4 10TB disks and then install Qradar on top of the Redhat install , known as a software install

     

    https://www.ibm.com/docs/en/qsip/7.5?topic=installations-qradar-software

     

    https://www.ibm.com/docs/en/qsip/7.5?topic=recovery-backup-qradar-configurations-data

     

    https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/installation_guide/sect-disk-partitioning-setup-x86

     

     

    I can't see any other questions on the case.

     

    If you have wish to escalate this further I would ask you to reach out to your account manager for guidance as Support can only advise on what our documentation states



    Sent from Outlook for iOS
    Unless stated otherwise above:
    Kyndryl Hungary Korlátolt Felelősségű Társaság / Kyndryl Hungary Llc
    8000 Székesfehérvár, Berényi út 72-100. 35. ép
    Cg.07-09-031714 - registering court: Székesfehérvári Törvényszék Cégbírósága





  • 13.  RE: QRadar /store disk expansion

    Posted Fri April 19, 2024 07:15 PM

    Thank you very much for Laszlo pasting the email response from IBM. I got the answer.



    ------------------------------
    Umamaheshwara Manekar
    ------------------------------