fkeles

qradar-boot-volume-grow.sh

Jan 2nd, 2026
52
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Bash 5.26 KB | Software | 0 0
  1. Mount Point Current Size    Proposed Size   Why?
  2. / (root)    20 GB   100 GB  Gives the OS breathing room for updates and temp files.
  3. /opt    14 GB   200 GB  QRadar binaries and many extensions/apps live here.
  4. /var/log    18 GB   500 GB  Critical. This is where QRadar stores active logs.
  5. /storetmp   15 GB   500 GB  Used for temporary data processing and backups.
  6. /var    8 GB    50 GB   General system variable data.
  7. Free Space  0 GB    ~500 GB Keep this unallocated. LVM allows you to grow any folder instantly later if it gets full.
  8.  
  9.  
  10. fdisk /dev/sda
  11.  
  12. [root@qradar-20260102-1919 ~]# fdisk /dev/sda
  13.  
  14. The device presents a logical sector size that is smaller than
  15. the physical sector size. Aligning to a physical sector (or optimal
  16. I/O) size boundary is recommended, or performance may be impacted.
  17. Welcome to fdisk (util-linux 2.23.2).
  18.  
  19. Changes will remain in memory only, until you decide to write them.
  20. Be careful before using the write command.
  21.  
  22.  
  23. Command (m for help): p
  24.  
  25. Disk /dev/sda: 2147.5 GB, 2147483648000 bytes, 4194304000 sectors
  26. Units = sectors of 1 * 512 = 512 bytes
  27. Sector size (logical/physical): 512 bytes / 4096 bytes
  28. I/O size (minimum/optimal): 4096 bytes / 1048576 bytes
  29. Disk label type: dos
  30. Disk identifier: 0x0000db86
  31.  
  32.    Device Boot      Start         End      Blocks   Id  System
  33. /dev/sda1   *        2048     2099199     1048576   83  Linux
  34. /dev/sda2         2099200     2508799      204800    6  FAT16
  35. /dev/sda3         2508800   255852543   126671872   8e  Linux LVM
  36.  
  37. Command (m for help): d
  38. Partition number (1-3, default 3): 3
  39. Partition 3 is deleted
  40.  
  41. Command (m for help): n
  42. Partition type:
  43.    p   primary (2 primary, 0 extended, 2 free)
  44.    e   extended
  45. Select (default p): p
  46. Partition number (3,4, default 3): 3
  47. First sector (2508800-4194303999, default 2508800):
  48. Using default value 2508800
  49. Last sector, +sectors or +size{K,M,G} (2508800-4194303999, default 4194303999):
  50. Using default value 4194303999
  51. Partition 3 of type Linux and of size 2 TiB is set
  52.  
  53. Command (m for help): t
  54. Partition number (1-3, default 3): 3
  55. Hex code (type L to list all codes): 31
  56. Changed type of partition 'Linux' to 'unknown'
  57.  
  58. Command (m for help): t
  59. Partition number (1-3, default 3): 3
  60. Hex code (type L to list all codes): L
  61.  
  62.  0  Empty           24  NEC DOS         81  Minix / old Lin bf  Solaris        
  63.  1  FAT12           27  Hidden NTFS Win 82  Linux swap / So c1  DRDOS/sec (FAT-
  64.  2  XENIX root      39  Plan 9          83  Linux           c4  DRDOS/sec (FAT-
  65.  3  XENIX usr       3c  PartitionMagic  84  OS/2 hidden C:  c6  DRDOS/sec (FAT-
  66.  4  FAT16 <32M      40  Venix 80286     85  Linux extended  c7  Syrinx        
  67.  5  Extended        41  PPC PReP Boot   86  NTFS volume set da  Non-FS data    
  68.  6  FAT16           42  SFS             87  NTFS volume set db  CP/M / CTOS / .
  69.  7  HPFS/NTFS/exFAT 4d  QNX4.x          88  Linux plaintext de  Dell Utility  
  70.  8  AIX             4e  QNX4.x 2nd part 8e  Linux LVM       df  BootIt        
  71.  9  AIX bootable    4f  QNX4.x 3rd part 93  Amoeba          e1  DOS access    
  72.  a  OS/2 Boot Manag 50  OnTrack DM      94  Amoeba BBT      e3  DOS R/O        
  73.  b  W95 FAT32       51  OnTrack DM6 Aux 9f  BSD/OS          e4  SpeedStor      
  74.  c  W95 FAT32 (LBA) 52  CP/M            a0  IBM Thinkpad hi eb  BeOS fs        
  75.  e  W95 FAT16 (LBA) 53  OnTrack DM6 Aux a5  FreeBSD         ee  GPT            
  76.  f  W95 Ext'd (LBA) 54  OnTrackDM6      a6  OpenBSD         ef  EFI (FAT-12/16/
  77. 10  OPUS            55  EZ-Drive        a7  NeXTSTEP        f0  Linux/PA-RISC b
  78. 11  Hidden FAT12    56  Golden Bow      a8  Darwin UFS      f1  SpeedStor      
  79. 12  Compaq diagnost 5c  Priam Edisk     a9  NetBSD          f4  SpeedStor      
  80. 14  Hidden FAT16 <3 61  SpeedStor       ab  Darwin boot     f2  DOS secondary  
  81. 16  Hidden FAT16    63  GNU HURD or Sys af  HFS / HFS+      fb  VMware VMFS    
  82. 17  Hidden HPFS/NTF 64  Novell Netware  b7  BSDI fs         fc  VMware VMKCORE
  83. 18  AST SmartSleep  65  Novell Netware  b8  BSDI swap       fd  Linux raid auto
  84. 1b  Hidden W95 FAT3 70  DiskSecure Mult bb  Boot Wizard hid fe  LANstep        
  85. 1c  Hidden W95 FAT3 75  PC/IX           be  Solaris boot    ff  BBT            
  86. 1e  Hidden W95 FAT1 80  Old Minix      
  87. Hex code (type L to list all codes): 8e
  88. Changed type of partition 'unknown' to 'Linux LVM'
  89.  
  90. Command (m for help): w
  91. The partition table has been altered!
  92.  
  93. Calling ioctl() to re-read partition table.
  94.  
  95. WARNING: Re-reading the partition table failed with error 16: Device or resource busy.
  96. The kernel still uses the old table. The new table will be used at
  97. the next reboot or after you run partprobe(8) or kpartx(8)
  98. Syncing disks.
  99.  
  100.  
  101. [root@qradar-20260102-1919 ~]# partprobe /dev/sda
  102. [root@qradar-20260102-1919 ~]# pvresize /dev/sda3
  103.  Physical volume "/dev/sda3" changed
  104.  1 physical volume(s) resized or updated / 0 physical volume(s) not resized
  105. [root@qradar-20260102-1919 ~]# vgs
  106.  VG   #PV #LV #SN Attr   VSize VFree
  107.  rhel   1   9   0 wz--n- 1.95t 1.83t
  108.  
  109. # Expand / (root) to 100 GB:
  110. lvextend -r -L 100G /dev/mapper/rhel-root
  111.  
  112. # Expand /opt to 200 GB:
  113. lvextend -r -L 200G /dev/mapper/rhel-opt
  114.  
  115. # Expand /var/log to 500 GB:
  116. lvextend -r -L 500G /dev/mapper/rhel-var_log
  117.  
  118. # Expand /storetmp to 500 GB:
  119. lvextend -r -L 500G /dev/mapper/rhel-storetmp
  120.  
  121. # Expand /var to 50 GB:
  122. lvextend -r -L 50G /dev/mapper/rhel-var
Advertisement
Add Comment
Please, Sign In to add comment