IBM Support

QRadar Can Send too Many Email Notifications about Partitions Status Change

Troubleshooting


Problem

QRadar users can see their email inboxes filled with disk status change notifications though the usage is less than the threshold configured. It does not cause any harm to the deployment, but you have to spend much time cleaning these notification emails, and it is time consuming.

Symptom

When you start receiving emails with a content like below, you are experiencing the issue. 
REMINDER: Disk usage levels on hostname have changed.

Disk usage has changed by 1.0% since the last alert. 
Actively Monitored Partitions:
The partition '/store' is in SUBNOMINAL state with 85.0% disk usage.
The partition '/opt' is in NORMAL state with 36.0% disk usage.
The partition '/' is in NORMAL state with 9.0% disk usage.
The partition '/transient' is in NORMAL state with 1.0% disk usage.
The partition '/storetmp' is in NORMAL state with 1.0% disk usage.
Passively Monitored Partitions:
The partition '/var/log' is in NORMAL state with 12.0% disk usage.
The partition '/var' is in NORMAL state with 6.0% disk usage.
The partition '/var/log/audit' is in NORMAL state with 5.0% disk usage.
The partition '/home' is in NORMAL state with 4.0% disk usage.
The partition '/tmp' is in NORMAL state with 2.0% disk usage.

Cause

When the free space on the (/store) partition is less than 750 GB, IBM QRadar starts sending warning notification about the partition usage and continues until the partition size is greater than 750 GB. Because /store partition is subnominal, it does not matter what the usage percentage is.

Resolving The Problem

When you start receiving these emails, check the current disk partitions usage.
# df -h
Filesystem                        Size  Used Avail Use% Mounted on
devtmpfs                           16G     0   16G   0% /dev
tmpfs                              16G  8.0K   16G   1% /dev/shm
tmpfs                              16G  1.7G   15G  11% /run
tmpfs                              16G     0   16G   0% /sys/fs/cgroup
/dev/mapper/rootrhel-root          37G  3.1G   34G   9% /
/dev/sda3                          32G  4.1G   28G  13% /recovery
/dev/mapper/rootrhel-storetmp      15G   36M   15G   1% /storetmp
/dev/sda2                        1014M  312M  703M  31% /boot
/dev/mapper/rootrhel-tmp          3.0G   41M  3.0G   2% /tmp
/dev/mapper/rootrhel-opt           13G  4.6G  8.0G  37% /opt
/dev/mapper/rootrhel-home        1014M   33M  982M   4% /home
/dev/mapper/storerhel-store       2.4T  2.0T  383G  85% /store
/dev/mapper/storerhel-transient   103G   33M  103G   1% /transient
/dev/mapper/rootrhel-var          5.0G  260M  4.8G   6% /var
These notifications are safe if you can manually confirm with df -h command that you have sufficient free space on (/store) partition.  Yet, if you have enough free space but it is less than 750 GB and want to stop receiving these emails then the permanent solution is to free space on the (/store) partition, so that the free space is always greater 750 GB. 

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000cwtrAAA","label":"Rules"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]

Document Information

Modified date:
05 October 2021

UID

ibm16479977