FortiAnalyzer Collector Mode Pros and Cons
Hi Everyone. I'm considering my options for log collecting and analysis using the FortiAnalyzer product. I had been using a 1000c in analyzer mode but am finding that my device is overwhelmed and overworked. I'm averaging around 1200 logs per second with bursts going into 3000+. In my infrastructure I have two 1000c's and one Analyzer VM at my disposal to achieve success.
What exactly are the benefits to running collector mode instead of analyzer mode?
I was under the impression that collector mode wasn't necessarily building a database as it collects logs but when I review my disk usage I'm noticing my devices are still using a significant amount of disk space for database. Should I expect to still have to use disk space for database even if in collector mode?
