FortiSIEM
FortiSIEM provides Security Information and Event Management (SIEM) and User and Entity Behavior Analytics (UEBA)
mbenvenuti
Staff
Staff
Article Id 356471
Description This article describes how to calculate the total raw event size usage.
Scope FortiSIEM from v7.2.2.
Solution

When an estimate is required for GB/day license or simply get the amount of received and used by an org, devices, etc - there are two ways of doing it from 7.2.2 version of FortiSIEM:

 

  1. Use PH_SYSTEM_RAW_EVENT_SIZE event.

This event is a system event reporting the raw event size of the last 15 minutes.

From Analytics menu, run the query with:

  • Filter: 'Event Type = PH_SYSTEM_RAW_EVENT_SIZE AND System Event Category IN 3'
  • Display Field: 'SUM(Total Bytes64)'
  • Time range absolute based on a chosen day.

Example:

 

gbperday1.png

 

  1. Use 'Raw Event Log Size' event attribute.

All events have their sizes calculated when received on FortiSIEM. This calculation is stored in the 'Raw Event Log Size' attribute. This enables the size calculation of Organizations, devices, etc.

 

For example:

 

gbperday2.png

 

Contributors