Hey folks, hoping to get some shared experiences here. We applied the latest cumulative patch (let's call it CP-2024-Q2) to our QRadar 7.5.0 environment over the weekend, and since then, our pipeline for log ingestion and correlation is crawling.
Specifically, our event processor performance seems to have taken a massive hit. Pre-patch, we were comfortably parsing around 12,000 EPS (events per second) with our hardware. Now, we're struggling to maintain 5,000 EPS. The CPU on our EP appliances is constantly pegged at 90%+, where it used to sit around 60-65% under the same load.
What we've checked so far:
* Confirmed all services are up and green in the "Admin" tab.
* No obvious errors in `/var/log/qradar.log` or `qradar.error`.
* Our custom DSM parsing rules didn't change.
* We're not seeing an increase in incoming traffic.
It *feels* like a parsing or indexing inefficiency introduced in the patch. I'm curious if anyone else has hit this and found a smoking gun.
Has anyone else rolled this patch out and benchmarked the before/after? I'm especially interested if you've seen:
* Increased memory or CPU on Event Processors
* Changes in the "Event Pipeline" performance metrics
* Any specific log sources or DSM types that now seem more expensive
We're about to start diving into `grep`-ing through the patch release notes more thoroughly, but community intel would be awesome. If you found a config tweak or a rollback was necessary, I'd love to hear it.
-pipelinepilot
Pipeline Pilot