Skip to main content
usmansa1
Visitor III
November 1, 2024
Question

How to obtain logs per second (LPS) from already deployed firewalls?

  • November 1, 2024
  • 2 replies
  • 2999 views

This post will help in estimation/adjustment of an important quantity Logs per second (LPS). Logs per second is a quantity which is required for calculating the storage size of Fortianalyzer during the deployment process. As mentioned in Fortianalyzer administration guide, generally, the traffic logs are equivalent to the sessions generated on the Firewall, therefore taking this as a base point, we can check the sessions generated on each firewall per day. This can be obtained from FortiGate statistics report  We can fetch the report by navigating to Log & Report >> Reports 

On reports we can see the total number of sessions generated per day. Taking an average of 7 to 14 days will give us an idea of average sessions generated per day for that particular firewall, which can then be converted into the traffic logs generated per day. Dividing that number with 86400 will give us LPS. 

 

Each security service  also contributes in overall log generation. An estimation for each security service is also require to be added in original session/traffic log estimation. The estimation for each security service is also present in Administrative guide of Fortianalyzer. This whole exercise will give us a rough number. We can later add a suitable margin to the final value. This value will be a good start in Design process for Fortianalyzer. Once the deployment is done we can check the actual log rate from Fortianalyzer by using the command "diagnose fortilogd log-rate ". Later on adjustment can be done with the actual log rate. 

 

Corrections are welcome 

 

2 replies

usmansa1
usmansa1Author
Visitor III
November 2, 2024

that is the post mate 

swagare2
New Member
November 9, 2024

@usmansa1 wrote:

This post will help in estimation/adjustment of an important quantity Logs per second (LPS). Logs per second is a quantity which is required for calculating the storage size of Fortianalyzer during the deployment process. As mentioned in Fortianalyzer administration guide, generally, the traffic logs are equivalent to the sessions generated on the Firewall, therefore taking this as a base point, we can check the sessions generated on each firewall per day. This can be obtained from FortiGate statistics report  We can fetch the report by navigating to Log & Report >> Reports 

On reports we can see the total number of sessions generated per day. Taking an average of 7 to 14 days will give us an idea of average sessions generated per day for that particular firewall, which can then be converted into the traffic logs generated per day. Dividing that number with 86400 will give us LPS. 

 

Each security service  also contributes in overall log generation. An estimation for each security service is also require to be added in original session/traffic log estimation. The estimation for each security service is also present in Administrative guide of Fortianalyzer. This whole exercise will give us a rough number. We can later add a suitable margin to the final value. This value will be a good start in Design process for Fortianalyzer. Once the deployment is done we can check the actual log rate from Fortianalyzer by using the command "diagnose fortilogd log-rate ". Later on adjustment can be done with the actual log rate. 

 

Corrections are welcome 

 


i got this solved,...

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!