High disk usage or disk is full?
QRadar has two different partition tables based on the QRadar version, 7.2.x vs 7.3.x, that would determine the starting point for the troubleshooting process. By default, the QRadar disk sentry check runs every 60 seconds and looks for high disk usage across the QRadar partitions. If any of these partitions exceed 90% usage, a warning notification is sent to the UI. For the partitions critical to system functionality, if the partition usage grows above 95%, system services will be stopped to avoid the partition becoming completely full and possibly causing further issues.