FAZ VM Log Throttle
- November 7, 2019
- 1 reply
- 4744 views
I have a FAZVM hosted on Dell Compellent (mostly flash) and Dell R630 servers, vSphere 6.5U3. The VM has 16G RAM and 8vCPUs. We have a 2GB/Day license and currently consume ~1.5G/day. As far as I can tell storage capacity and IOPs are not rate limiting but my receive rate never exceeds 150 logs/sec. Insertion rate is consistently less than 60s.
We have two 501Es in A/P HA. We are outputting logs to a Syslog destination in addition to the FAZ. It does not appear that we are dropping logs/traffic but the receive rate appears very flat during what would be peak periods. See attached.
Looking through docs in older FortiOS, it appears there was a min and max buffer setting for FAZ settings on the Fortigate but that is not available in FortiOS 6.0.5. Our FAZ is the same version. We try and log everything including denies so there should be enough volume. Firewall is protecting ~500 devices (desktops/laptops/mobile) and servers such as Exchange. It just seems strange that the receive rate is so flat during business hours. If anyone has any ideas of what to test check, I'd appreciate it.
