Topic: C1000-140 topic 1 question 34

Which QRadar log file contains information about the rates of EPS?

A.
/var/log/eps.log
B.
/var/qradar.log
C.
/var/log/qradar.log
D.
/var/log/qradar.old

Re: C1000-140 topic 1 question 34

Answer is "C"

To view EPS rates from the command-line interface of the QRadar appliance,
type: less -iS  /var/log/qradar.log | grep peak

Example
Incoming raw event rate (5s: 221.20 eps), (10s: 167.90 eps), (15s: 150.67 eps), (30s: 114.40 eps), (60s: 130.25 eps), (300s: 129.94 eps), (900s: 129.94 eps). Peak in the last 60s: 229.20 eps. Max Seen 301.40 eps. EC Throttles/5s (60s: 0.00). Total EC Throttles in the last 60s: 0. Total EC Throttles: 2. License Threshold: 5020.00