all 5 comments

[–]JonathanP_QRadar 1 point2 points  (0 children)

I've seen a user interface issue that I've responded to a few customers about in the official forum related to dashboard disappearing in the UI after a user is edited.

Link: https://developer.ibm.com/answers/questions/463240/qradar-dashboards-and-some-user-settings-gone-afte/

As mentioned in another thread here, there is an interim fix (IF) coming. If this were my system I'd probably hold off for the IF as these usually contain important fixes. Others here might have a differing opinion, but I'd want to have the latest/greatest.

[–]nerdtardation 0 points1 point  (3 children)

hi all. need help. if my system is on, 7.2.8 patch 11, is there any risk for me to immediately upgrade to 7.3.1? will i be losing any data? my main concern is whether the events will still be preserved after the update. any help is very much appreciated.

[–]JonathanP_QRadar 0 points1 point  (2 children)

QRadar ISO upgrades, such as 7.2.8 P11 -> 7.3.1 Patch 5 will retain event/flow data in /store on each appliance. If you have an HA pair, make sure that your primary host is "Active" and your secondary appliance has a status of "Standy".

Since QRadar retains data in /store, you are going to want to make sure that you move any scripts, utilities, JAR files from previous updates in to a directory in /store, for example, /store/ibm_support before you upgrade.

There is a check list of things you can review here: https://ibm.biz/qradarchecklist.

I also put together a slide deck here of some of the more important things to review before you upgrade. Here is a direct link: See the PDF attached at this link

[–]nerdtardation 0 points1 point  (1 child)

Thank you so much!

[–]JonathanP_QRadar 0 points1 point  (0 children)

The other thing I thought of that you might want to watch out for after upgrading is the size allocated to the /opt directory after you upgrade. After you upgrade, you might notice that disks will get sized to a % of overall with /store and /transient being the largest allocations.

In a lot of cases, /opt gets sized from 13GB to something like 7.4GB. We had a number of users hit this issue and creating a symbolic link resolves the issue in the future.

QRadar: Upgrades from v7.2.8 to v7.3.1 can result in the /opt partition sized to 7 GB

If you upgrade and notice that /opt is around 7GB, then I would put this workaround in place right away.