FortiSIEM Discussions
adem_netsys
Contributor II

Expensive rule Discover

Hi team,

 

I want to check whether the custom rules cause performance issues. Has anyone tested this before? How can I go about it? I'm not talking about going through each rule individually and performing regex checks.

1 REPLY 1
sioannou
Contributor

@adem_netsys ,

 

Not sure if there is an official guide on this there is an article on the rule performance and best practises guide. (Good practices and How to troubleshoot ru... - Fortinet Community)

 

In reality is very difficult to gauge this kind of metrics, since there are no individual rule performance metrics. How we do it internally is that we monitor the CPU utilisation and the process utilisation before and after the insertion or the modification of the rule vs EPS. This gives us a good indication on the overall impact of the rule to the system. 

I would pay close attention at 00:00 when the AI Models start training and main maintenance operations of the SIEM start. 

 

Depending on your deployment you could replicate all the logs on a test system and benchmark the rule there. 

 

Regards,

 

S