Dear FortiSIEM community,
I am planning a deployment with two workers, two collectors in HA and supervisor.
I don't want the supervisor to store any logs, I just want it to control and manage the cluster.
Initially I did not use any disk for ClickHouse, but I learnt in this post that it is a requirement even though supervisor will not store any logs. I provisioned a 60 GB ClickHouse disk and formed the cluster - see in the screenshots. When I checked the EPS distributed to the cluster nodes, I noticed that supervisor is receiving logs even though in is not defined in the Event Upload Workers and there is no shard assigned to it (no data node). I also configured the collectors to send logs only to the worker nodes.
Could you please explain whether this is expected behavior?
Does supervisor distribute the logs it collects to worker nodes to store in this case?
Many thanks,
Jan
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
| User | Count |
|---|---|
| 77 | |
| 25 | |
| 15 | |
| 10 | |
| 10 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.