Question & Answer
When you use both options Forward and Drop, in the internal QRadar logs the license is consumed, but the system gives you back that license in the next interval, for example:
Here we see that the license is taken:
Dec 23 12:39:19 ::ffff:10.10.10.3 <...> Incoming raw event rate (5s: 868.80 eps), (10s: 785.90 eps), (15s: 814.07 eps), (30s: 813.80 eps), (60s: 840.82 eps), (300s: 799.53 eps), (900s: 799.53 eps). Peak in the last 60s: 901.00 eps. Max Seen 938.00 eps. EC Throttles/5s (60s: 0.00). Total EC Throttles in the last 60s: 0. Total EC Throttles: 8. Appliance Threshold: 5020.00
And here we can see that the system gives back this license:
Dec 23 12:33:09 ::ffff:10.10.10.3 <...> License giveback Event count (SensorDevices [60s: 106.57 eps]) (Events Dropped [60s: 735.13 eps]) (Events Log Only [60s: 0.00 eps]) (Total [60s: 841.70 eps])
Was this topic helpful?
19 May 2021