| Description | This article describes how to handle 'High Inter-shard Storage Gap between ClickHouse Workers' and 'High Intra-shard Storage Gap between ClickHouse Workers' Alerts. | 
| Scope | FortiSIEM. | 
| Solution | 
 FortiSIEM may trigger one or both of the following alerts in environments using ClickHouse as the event database: 
 These alerts are raised when there is a significant difference in disk usage between shards or replicas, which can result in degraded query performance, uneven resource utilization, and increased latency in data processing. 
 Cause: A storage gap occurs when one shard or replica stores significantly more data than the others. 
 
 Solution: To resolve the High Inter-shard Storage gap/High Intra-shard Storage Gap between ClickHouse Workers alert, follow these steps: 
 Run the following command on the node that has the out-of-order issue: 
 # /opt/phoenix/bin/clickhouse-rebalance-partitions 
 This redistributes partitions evenly across shards and replicas. After rebalancing has been performed, monitor the alerts for a few hours to verify alerts no longer trigger.  | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.