QRadar: Events might be dropped from a QRadar device when the incoming events matching Log Only (Exclude Analytics) is more than the allocated EPS on the QRadar device.

Why do events get dropped from a QRadar device that has a routing rule set to Log Only (Exclude Analytics) when incoming events are more than the allocated Events Per Second (EPS) on the QRadar device?


Let's consider that a QRadar device with a license of 500 EPS. 
Let's also assume the incoming event rate to be 1000 EPS, and all the incoming events are set to Log Only (Exclude Analytics) in the routing rules.
Though "Log-only" option does not consume license effectively, but there could be events dropped in this situation.
The reason for the observation is the fact that the license throttle happens before the events are routed by the routing rules. Thus, the additional EPS causes the license exceeded the threshold message to occur and events to drop.
Even-though, Log Only (Exclude Analytics) credits back 100% to the license as part of license giveback. It is valid only when events that match the Log Only (Exclude Analytics) routing rule is less than or equal to the EPS allocated on that system.
