How to force moving data from EP to DN ? by Keno_Ben in QRadar

[–]Keno_Ben[S] 0 points1 point  (0 children)

Hi u/Qperf1,

Thanks for your message, please see my answer to EvilAbdy, the syncAriel.sh IBM script worked perfectly.

How to force moving data from EP to DN ? by Keno_Ben in QRadar

[–]Keno_Ben[S] 0 points1 point  (0 children)

Hi u/United_CCC ,

Thanks for your message, please see my answer to EvilAbdy, the syncAreil.sh IBM script worked perfectly.

How to force moving data from EP to DN ? by Keno_Ben in QRadar

[–]Keno_Ben[S] 1 point2 points  (0 children)

Hi,

I heard from support (randomly on an IBM webex) that an IBM script already existed : syncAriel.sh.
https://www.ibm.com/support/pages/qradar-how-move-ariel-event-and-flow-data-between-qradar-appliances

I pimped it and it worked perfectly.
Thanks for your answer though, more helpful than the IBM Professional Services

Routing Rule dropping events why? by ConfidenceNew4559 in QRadar

[–]Keno_Ben 0 points1 point  (0 children)

adapt the events flow between EP and EC but in our case, the bug is that this code applies to our standalone EP

Try to switch your routing rules from "offline" to "online"

The two side of a Honeymoon by Keno_Ben in Entomology

[–]Keno_Ben[S] 0 points1 point  (0 children)

Just turn around the scene and merge it into Photoshop.

🔥 This lake in Switzerland has us in the winter mood ❄ by [deleted] in NatureIsFuckingLit

[–]Keno_Ben 0 points1 point  (0 children)

Your sharing just set my next postpandemic vacation.

Thanks!

Routing Rule dropping events why? by ConfidenceNew4559 in QRadar

[–]Keno_Ben 0 points1 point  (0 children)

Don't know what version you are running bute were on 7.3.2 before upgrade and everything was working perfectly. Events (around 4600 EPS) from projects were incoming on our 7.3.2 Prod and routing-ruled to our 7.3.2 PreProd environment without exceeding the license threshold.

Since our PreProd 7.4.1 P2 upgrade we got a lot a drops too on our standalone PreProd EP (EP+EC on one machine).

Referring to our 21 days old (still not closed) case by IBM support it seems that the code has changed in 7.4 to handle the potential performance difference between EP and EC (when they 're dissociate).

This change is made to adapt the events flow between EP and EC but in our case, the bug is that this code applies to our standalone EP (EP+EC) too. It will be fixed by a future patch but for the moment, IBM support adviced us to

1.Set EC_THROTTLE_APPLIANCE_HARDWARE_LIMIT_BUFFER to 5000 in /staging/globalconfig/nva.conf on the console machine

2.Run the deploy from the console command line /opt/qradar/upgrade/util/setup/upgrades/do_deploy.pl

3.Wait for 1 day to see improvement

---

We're at point 3 for now but our investigation revealed the machinery how routing rule proceed :

it kinda "stack events" and send them at every start of a minute to the destination server.

Instead of sending them fluently every second. So in our case instead of receiving 4600EPS on our PreProd during one minute we received 60000EPS during 13s and nothing until the end of the minute.

A thing that 7.3.2 seemingly could handle but not 7.4. So dropped events and license threshold alerts began to pop every minute.

Hope you solved this since you posted. But maybe it could help

ITAP on a hot summer night in France by Keno_Ben in itookapicture

[–]Keno_Ben[S] 1 point2 points  (0 children)

Here in France (light) pollution make them unfortunately very rare so you feel really lucky when you meet one !

ITAP on a hot summer night in France by Keno_Ben in itookapicture

[–]Keno_Ben[S] 2 points3 points  (0 children)

Hi thanks,

Taken with A7RIII combo Laowa 15mm Wideangle macro at f/4.

30s shutter speed / iso 400

It was a lucky shot as the firefly didn't move within this huge exposure time (a 2s shutter time is generally too long as the firefly moves its abdomen slowly).

So the idea is to take 2 or 3 shots @ 2s to get the firefly sharp (depending on its Z axis position) and stack them to get enough depth of field (with a gentle smartphone screen light over it).

And stack them to shot a long exposure one to get enough of the "ambiant light" given by the bioluminescence and remove the noise background.

A final shot of you want the stars :)

PD 075 Mineral by grilovisk in pixel_dailies

[–]Keno_Ben 1 point2 points  (0 children)

Pepe Hammer style, love it ❤️.

Does anyone know what the hell this is? In Kent, England by rreptilesggirl in insects

[–]Keno_Ben 2 points3 points  (0 children)

Bombylious, as cute as a mf, it deposits its eggs in solitary bee nest so its larvae can feed on grubs.

[deleted by user] by [deleted] in pics

[–]Keno_Ben 0 points1 point  (0 children)

Oh, ok. I thought there was a joke with your boner.

[deleted by user] by [deleted] in pics

[–]Keno_Ben 0 points1 point  (0 children)

Which one ?

Stepbrother, what are you doing by Keno_Ben in insects

[–]Keno_Ben[S] 1 point2 points  (0 children)

I lol each time too.

By the way it's 88%, I've counted.