No problem, one thing I forgot to mention is that if you are pushing your license limit that you get a 5GB of event buffer and 5GB of flow buffer per appliance. If you scale your deployment, adding a new appliance not only gives you capability, but also a separate 5GB buffer where events are received. Scaling your deployment gives you more resources, buffer, so you can add a Event Collector or Disconnected Log Collector (DLCs).
If you are having issues and need to receive events DLC on a Linux host, you can gain buffer without cost.
------------------------------
Jonathan Pechta
QRadar Support Content Lead
Support forums: ibm.biz/qradarforums
jonathan.pechta1@ibm.com------------------------------
Original Message:
Sent: Tue February 28, 2023 08:07 AM
From: Abdul Quadeer
Subject: temporary queue
Thank you, Jonathan Pechta.
------------------------------
Abdul Quadeer
Original Message:
Sent: Mon February 27, 2023 10:31 PM
From: Jonathan Pechta
Subject: temporary queue
The event and flow burst handling buffer can be increased, but it is typically not recommended. As 5GB can hold a huge volume of events, increasing the buffer does not solve the license issues. As the appliance license needs to be under the limit and in recovery, always pushing up against your license never allows the volume to decrease at any meaningful rate. You either need to size the license properly with an increase or start using some routing rules to drop low security value events. If 5GB can hold 1.5 million events, and you only have 2k EPS the buffer needs to be able to clear in a timely manner for correlation. Having full buffers and increasing the burst handling capacity is not solving the problem, just delaying it.
Can support increase the buffer size? Yes.
Does support recommend this action? No.
You should talk to your sales rep to see about an increase in your license capacity so you can allocate more EPS to the appliance so you are in recovery more often. Optionally, you can drop low security value events, which would give you EPS back on the EPS license interval.
------------------------------
Jonathan Pechta
QRadar Support Content Lead
Support forums: ibm.biz/qradarforums
jonathan.pechta1@ibm.com
Original Message:
Sent: Mon February 27, 2023 11:26 AM
From: Abdul Quadeer
Subject: temporary queue
Hi,
Is it possible and advisable to increase the size of the temporary queue from 5GB to something like 20GB? If yes, then what will be the impact.
Thanks.
------------------------------
Abdul Quadeer
------------------------------