IBM Security QRadar

 View Only
  • 1.  temporary queue

    Posted Mon February 27, 2023 11:27 AM

    Hi,

    Is it possible and advisable to increase the size of the temporary queue from 5GB to something like 20GB? If yes, then what will be the impact.

    Thanks.



    ------------------------------
    Abdul Quadeer
    ------------------------------


  • 2.  RE: temporary queue
    Best Answer

    Posted Mon February 27, 2023 10:31 PM
    Edited by Jonathan Pechta Tue February 28, 2023 12:10 PM

    The event and flow burst handling buffer can technically be increased, but it is not recommended and not an action support completes for end users. As 5GB can hold a huge volume of events, increasing the buffer does not solve the license issues. As the appliance license needs to be under the limit and in recovery, always pushing up against your license never allows the volume to decrease at any meaningful rate. You either need to size the license properly with an increase or start using some routing rules to drop low security value events. If 5GB can hold 1.5 million events, and you only have 2k EPS the buffer needs to be able to clear in a timely manner for correlation. Having full buffers and increasing the burst handling capacity is not solving the problem, just delaying it. 

    Does support recommend this action? No. 

    You should talk to your sales rep to see about an increase in your license capacity so you can allocate more EPS to the appliance so you are in recovery more often. Optionally, you can drop low security value events, which would give you EPS back on the EPS license interval. 


    Edit: Updated post as I was informed that support does not increase buffer sizing for end users. I added in another thread that for some users, it might be better to scale up to get more buffer as it add capacity + event buffer by adding another appliance.


    ------------------------------
    Jonathan Pechta
    QRadar Support Content Lead
    Support forums: ibm.biz/qradarforums
    jonathan.pechta1@ibm.com
    ------------------------------



  • 3.  RE: temporary queue

    Posted Tue February 28, 2023 08:08 AM

    Thank you, Jonathan Pechta.



    ------------------------------
    Abdul Quadeer
    ------------------------------



  • 4.  RE: temporary queue

    Posted Tue February 28, 2023 03:26 PM

    No problem, one thing I forgot to mention is that if you are pushing your license limit that you get a 5GB of event buffer and 5GB of flow buffer per appliance. If you scale your deployment, adding a new appliance not only gives you capability, but also a separate 5GB buffer where events are received. Scaling your deployment gives you more resources, buffer, so you can add a Event Collector or Disconnected Log Collector (DLCs).


    If you are having issues and need to receive events DLC on a Linux host, you can gain buffer without cost. 



    ------------------------------
    Jonathan Pechta
    QRadar Support Content Lead
    Support forums: ibm.biz/qradarforums
    jonathan.pechta1@ibm.com
    ------------------------------