IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Tenant Log Retention

    Posted Sun February 07, 2021 10:33 AM

    I had Log retention on each tenant for 1.2 months by mistake now I can't find any log in the log activity before that hence I have all the logs in the ariel directory how can I get the logs back on the log activity tab?



    #QRadar
    #Support
    #SupportMigration


  • 2.  RE: Tenant Log Retention

    Posted Tue February 09, 2021 03:41 PM

    If you had Event Retention configured to delete when disk space is required, your events might be purged from the system. If you modified your domain and tenant structure, your older events would still be categorized under that domain. For example, you create a domain as Domain A on 1 January 2020. On 1 Feb 2020, you modify your domain structure and have events going to DomainZ. As events have domain tags added when they are parsed, doing a search between 1 Jan and 1 Feb might require you to search for DomainA and DomainZ to view all events as we do not modify payloads.

    I would probably get a case opened to verify this issue. If you still see payloads and records in /store/ariel/ for your time frame on the appliance, they are likely still there and not removed by Event Retention cleanup. However, you might need to modify your search or have support confirm you are not hitting a known issue.

    You didn't list your QRadar version or describe the type of search you were doing, but you could potentially be hitting an AQL issue if you are doing an Advanced search.I still think you might want someone to confirm your search results or that you are not experiencing an issue. For example:



    #QRadar
    #Support
    #SupportMigration