In the Admin > Device > Parsers many (all) are enabled but many are for devices we do not have in our environment. Does having unused parsers enabled affect the SIEM performance? Would it make sense to disable them?
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
Parsers are evaluated in the order they appear. If there is a match the parser is utilised and evaluation stops at the parser. In general yes you can disable the ones not utilised but in general the Parser system is a very high performance system to be in a position to manage EPS in the millions in certain deployment.
The final decision is yours, disabling them does not cause any harm but be very careful with Parsers that are utilised for multiple sources (like CEF, JSON etc).
Let me know if there are any additional questions.
Regards,
S
Hi,
Parsers are evaluated in the order they appear. If there is a match the parser is utilised and evaluation stops at the parser. In general yes you can disable the ones not utilised but in general the Parser system is a very high performance system to be in a position to manage EPS in the millions in certain deployment.
The final decision is yours, disabling them does not cause any harm but be very careful with Parsers that are utilised for multiple sources (like CEF, JSON etc).
Let me know if there are any additional questions.
Regards,
S
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.