Troubleshooting
Problem
QRadar users can see their email inboxes filled with disk status change notifications though the usage is less than the threshold configured. It does not cause any harm to the deployment, but you have to spend much time cleaning these notification emails, and it is time consuming.
Symptom
When you start receiving emails with a content like below, you are experiencing the issue.
REMINDER: Disk usage levels on hostname have changed.
Disk usage has changed by 1.0% since the last alert.
Actively Monitored Partitions:
The partition '/store' is in SUBNOMINAL state with 85.0% disk usage.
The partition '/opt' is in NORMAL state with 36.0% disk usage.
The partition '/' is in NORMAL state with 9.0% disk usage.
The partition '/transient' is in NORMAL state with 1.0% disk usage.
The partition '/storetmp' is in NORMAL state with 1.0% disk usage.
Passively Monitored Partitions:
The partition '/var/log' is in NORMAL state with 12.0% disk usage.
The partition '/var' is in NORMAL state with 6.0% disk usage.
The partition '/var/log/audit' is in NORMAL state with 5.0% disk usage.
The partition '/home' is in NORMAL state with 4.0% disk usage.
The partition '/tmp' is in NORMAL state with 2.0% disk usage.
Cause
When the free space on the (/store) partition is less than 750 GB, IBM QRadar starts sending warning notification about the partition usage and continues until the partition size is greater than 750 GB. Because /store partition is subnominal, it does not matter what the usage percentage is.
Resolving The Problem
When you start receiving these emails, check the current disk partitions usage.
# df -h
Filesystem Size Used Avail Use% Mounted on
devtmpfs 16G 0 16G 0% /dev
tmpfs 16G 8.0K 16G 1% /dev/shm
tmpfs 16G 1.7G 15G 11% /run
tmpfs 16G 0 16G 0% /sys/fs/cgroup
/dev/mapper/rootrhel-root 37G 3.1G 34G 9% /
/dev/sda3 32G 4.1G 28G 13% /recovery
/dev/mapper/rootrhel-storetmp 15G 36M 15G 1% /storetmp
/dev/sda2 1014M 312M 703M 31% /boot
/dev/mapper/rootrhel-tmp 3.0G 41M 3.0G 2% /tmp
/dev/mapper/rootrhel-opt 13G 4.6G 8.0G 37% /opt
/dev/mapper/rootrhel-home 1014M 33M 982M 4% /home
/dev/mapper/storerhel-store 2.4T 2.0T 383G 85% /store
/dev/mapper/storerhel-transient 103G 33M 103G 1% /transient
/dev/mapper/rootrhel-var 5.0G 260M 4.8G 6% /var
These notifications are safe if you can manually confirm with df -h command that you have sufficient free space on (/store) partition. Yet, if you have enough free space but it is less than 750 GB and want to stop receiving these emails then the permanent solution is to free space on the (/store) partition, so that the free space is always greater 750 GB.
Document Location
Worldwide
[{"Type":"MASTER","Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000cwtrAAA","label":"Rules"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]
Was this topic helpful?
Document Information
Modified date:
05 October 2021
UID
ibm16479977