Hello everyone,
I’m currently working on the design of a FortiSIEM deployment expected to handle 10,000 EPS, and I’d like to get some insights or recommendations from the community.
1 Supervisor
1 Worker
Collectors at each site (multiple sites)
ClickHouse for event storage
Before finalizing the architecture, I have a few questions about the design choices and database placement.
What are the main advantages of separating the Supervisor and Worker compared to using an all-in-one Supervisor setup (for a 10K EPS environment)?
Does it provide noticeable performance or scalability improvements in real-world deployments? or would be an all in one supervisor good enough (to optimize resources usage).
Where should ClickHouse ideally be installed — on the Supervisor or on the Worker?
My initial preference is to host ClickHouse on the Worker to reduce load on the Supervisor, but I’d like to confirm if that’s a recommended or supported approach.
If ClickHouse can (or should) reside on the Worker, how can I install and configure it there instead of the Supervisor?
If anyone has an official Fortinet KB or deployment guide covering this scenario, please share the reference.
I’d really appreciate feedback from anyone who has implemented or benchmarked a similar setup — especially around event storage design, deployment best practices, and operational lessons learned.
Thanks in advance for your help!
Hi @AEH,
Have a look at these documents:
I think, the NSE training (https://training.fortinet.com) also mentions the basics of ClickHouse deployment.
In general, my recommendation:
ClickHouse automatically comes with the default installation, you don't need to install anything additionally. You only need to configure it, depending on your needs (for needs: see sizing guide above). This is done in the admin config menu and you simply configure, test and deploy it on the GUI. In a simple setup (10k still is a low number), I would recommend one Supervisor as Keeper and two Workers as Replicas of one Shard can absolutely handle that. You might need to deploy more Keepers, in case you like HA things on the Supervisor.
Hope this helps.
Best,
Christian
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
| User | Count |
|---|---|
| 77 | |
| 25 | |
| 15 | |
| 10 | |
| 10 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.