<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic XSOAR incident in Qradar in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-incident-in-qradar/m-p/598058#M3616</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We are encountering a connection timeout issue when attempting to create incidents in Cortex XSOAR using a custom QRadar integration. Based on our observations, we suspect this issue is due to low IOPS on XSOAR, as low as 100, despite the IOPS being allocated as unlimited from the VM Console. We believe the low IOPS are causing delays in writing data to storage, which leads to late incident creation.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Environment Details:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Cortex XSOAR Version: [6.12 Build 857430]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Host OS: Red Hat Enterprise Linux 8.8 (Ootpa)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;XSOAR Host Specs:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;CPU: 16 cores&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Memory: 128 GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Storage: 2.2 TB SSD&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Allocated IOPS: Unlimited (as per VM console)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Symptoms:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Connection timeout when creating incidents.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Incident creation delayed significantly.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Host Utilization (from CLI):&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;CPU Usage (top):&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;top - 18:40:08 up 8 min, 1 user, load average: 3.35, 1.94, 0.91&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Tasks: 390 total, 1 running, 389 sleeping, 0 stopped, 0 zombie&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;%Cpu(s): 5.2 us, 0.9 sy, 0.0 ni, 78.4 id, 15.4 wa, 0.1 hi, 0.1 si, 0.0 st&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;RAM Usage (free -m):&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Mem: 128397 MB total, 112759 MB free, 9416 MB used, 6221 MB buff/cache&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Storage Usage (df -h):&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Filesystem Size Used Avail Use% Mounted on&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/dev/mapper/rhel-var 2.0T 499G 1.5T 25% /var&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;However, XSOAR app reports different numbers:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;CPU Usage (XSOAR Console): 96.39%&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Memory Usage (XSOAR Console): 8.48%&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Storage Usage (XSOAR Console): 405.099 GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We are not able to correlate these numbers with what is observed from the CLI. We’ve already checked the IOPS and confirmed it is set to unlimited from the VM console, and storage space seems sufficient.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Request: Could you please help us:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;1. Confirm whether the low IOPS could be the root cause of the connection timeout and delayed incident creation.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2. Understand why there discrepancy between the host utilization as reported by the XSOAR app and what is seen on the host CLI.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any suggestions and action plan urgently.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 18 Sep 2024 00:10:55 GMT</pubDate>
    <dc:creator>assubramania</dc:creator>
    <dc:date>2024-09-18T00:10:55Z</dc:date>
    <item>
      <title>XSOAR incident in Qradar</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-incident-in-qradar/m-p/598058#M3616</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We are encountering a connection timeout issue when attempting to create incidents in Cortex XSOAR using a custom QRadar integration. Based on our observations, we suspect this issue is due to low IOPS on XSOAR, as low as 100, despite the IOPS being allocated as unlimited from the VM Console. We believe the low IOPS are causing delays in writing data to storage, which leads to late incident creation.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Environment Details:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Cortex XSOAR Version: [6.12 Build 857430]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Host OS: Red Hat Enterprise Linux 8.8 (Ootpa)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;XSOAR Host Specs:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;CPU: 16 cores&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Memory: 128 GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Storage: 2.2 TB SSD&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Allocated IOPS: Unlimited (as per VM console)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Symptoms:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Connection timeout when creating incidents.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Incident creation delayed significantly.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Host Utilization (from CLI):&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;CPU Usage (top):&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;top - 18:40:08 up 8 min, 1 user, load average: 3.35, 1.94, 0.91&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Tasks: 390 total, 1 running, 389 sleeping, 0 stopped, 0 zombie&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;%Cpu(s): 5.2 us, 0.9 sy, 0.0 ni, 78.4 id, 15.4 wa, 0.1 hi, 0.1 si, 0.0 st&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;RAM Usage (free -m):&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Mem: 128397 MB total, 112759 MB free, 9416 MB used, 6221 MB buff/cache&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Storage Usage (df -h):&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Filesystem Size Used Avail Use% Mounted on&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/dev/mapper/rhel-var 2.0T 499G 1.5T 25% /var&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;However, XSOAR app reports different numbers:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;CPU Usage (XSOAR Console): 96.39%&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Memory Usage (XSOAR Console): 8.48%&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Storage Usage (XSOAR Console): 405.099 GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We are not able to correlate these numbers with what is observed from the CLI. We’ve already checked the IOPS and confirmed it is set to unlimited from the VM console, and storage space seems sufficient.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Request: Could you please help us:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;1. Confirm whether the low IOPS could be the root cause of the connection timeout and delayed incident creation.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2. Understand why there discrepancy between the host utilization as reported by the XSOAR app and what is seen on the host CLI.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any suggestions and action plan urgently.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 00:10:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-incident-in-qradar/m-p/598058#M3616</guid>
      <dc:creator>assubramania</dc:creator>
      <dc:date>2024-09-18T00:10:55Z</dc:date>
    </item>
    <item>
      <title>Re: XSOAR incident in Qradar</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-incident-in-qradar/m-p/598708#M3638</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In this case the correct assistance would be from your internal VM team so they can confirm the IOPS are as required by our documentation and if not they can implement the required changes.&lt;/P&gt;
&lt;P&gt;Once that has been cleared, we recommend you create a case to address question 2.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 02:10:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/xsoar-incident-in-qradar/m-p/598708#M3638</guid>
      <dc:creator>Ivetto</dc:creator>
      <dc:date>2024-09-25T02:10:24Z</dc:date>
    </item>
  </channel>
</rss>

