IBM Support

QRadar: How to configure the DLC buffer size for stored events to fit your needs

How To


Summary

Administrators might need to increase or decrease the buffer size from the default 50GB depending on the disk space available. For example, if the administrator set the minimum space of the root partition to 52GB and the buffer size is set to 50GB, disk space can reach 100% usage.

Objective

This guide explains how to change the settings to increase or decrease the buffer size.

Steps

For this scenario, the DLC disk space is set to 100GB on the root partition and the default buffer is increased to 75GB from the default 50GB.
  1. SSH into the QRadar Console.
  2. Stop the DLC service
    systemctls stop dlc
  3. In the /opt/ibm/si/services/dlc/conf/spilloverqueue.properties file there are 2 parameters that guide the default buffer size that can be edited:
    ecs-dlc_dlc_TCP_TO_QRADAR.max.file.size.mb=100
    ecs-dlc_dlc_TCP_TO_QRADAR.max.files=477
    The formula for total buffer size is as follows: max files * max file size = buffer size
    For this example, 477 files multiplied by the maximum file size of 100MB is approximately 50GB. We edit the file and increase the max.files parameter to 715, which equates to approximately 75GB.
    ecs-dlc_dlc_TCP_TO_QRADAR.max.files=715
  4. After you edit and save the properties file, start the DLC service.
    systemctl start dlc

    Result
    This change allows max buffer to be reached without causing disk space issues.  
     
Alternative procedure
If increasing the size of the disk space is not possible, you can reduce the maximum number of files to something more suitable. For example, if 52 GB is the maximum size on the root partition, then setting the max files to 238 files reduces the buffer to approximately 25GB.

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000cwt9AAA","label":"DLC"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]

Document Information

Modified date:
12 December 2022

UID

ibm16841283