The final outcome was as @Frank Eargle said - UBA. We had two different searches happening:
- Discover new Users - Searched for new users nightly instead of using our LDAP list only
- There was a cache profile job that runs to make the data on users available to the dashboard and cuts down load times when investigating. To resolve this issue we needed to add a line:
disable_profile_cache_task: true
to a config file. Not going to share that hear because I would not change config files unless you know what you are doing. Reach out to support if needed.
------------------------------
Russell Lieneman
------------------------------
Original Message:
Sent: Thu January 23, 2025 09:09 AM
From: Frank Eargle
Subject: Transient folder reciently filling up
We had one of our customers doing this and it turned out to be the UBA doing some huge searches (200K users). Once we knew what it was we put expiration on most of the reference sets relating to UBA, 4 month on the dormant for instance.
------------------------------
Frank Eargle
Original Message:
Sent: Wed January 22, 2025 09:40 AM
From: John Dawson
Subject: Transient folder reciently filling up
Hi Russell
If the files are being created at those specific times evry night is there a Cron job set to do something at those times?
What are the names of the files being created?
Thanks
------------------------------
John Dawson
Qradar Support Architect
IBM
Original Message:
Sent: Fri January 10, 2025 07:22 AM
From: Russell Lieneman
Subject: Transient folder reciently filling up
A few weeks ago we started seeing issues with the /transient folder hitting 90% almost nightly. I disabled all nightly reports and cleared the folder down to 23% last night and it was back up to 75% over night with the larger files being created at 00:30, 01:30, and 02:30. Is there a way to trace back what processes or searches are creating the files. We have not had the issues since we built the environment out years ago.
We have already tried:
- Addressing the expensive searches
- Disabled QDI
- Deleted large searches from the UI that are no longer needed.
- Followed tech notes to free up additional space in /transient.
Looking for a way to trace back what is creating the files and using up the space.
------------------------------
Russell Lieneman
------------------------------