- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Slash_Khalil ,
It really depends on your needs.
Have a look at the datasheets below and form your questions based on the product specifications.
For example: how much throughput/bandwidth? How much memory it needs? EPS in case of FortiSIEM?
-https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/FortiWeb.pdf
-https://docs.fortinet.com/document/fortisiem/6.6.5/sizing-guide/965243/fortisiem-sizing-guide#/docum...
If you have found a solution, please like and accept it to make it easily accessible for others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @Slash_Khalil , about Fortisiem following informations are tipically required:
1. How many EPS Fortisiem should ingested?
2. How many devices should be integrated with Fortisiem?
3. How many advanced agents (Linux and Windows) do you need?
4. Do you need UEBA license for advanced agents? UEBA is used on agents to generate incidents using machine learning algorithm.
5. Do you need a redundant infrastructure? If yes, you can implement an High availability solution then you need an additional license, otherwise if you want to implement a Disaster recovery solution you need the same licenses of primary fortisiem.
4. What are your data retention policies? E.g. do you want to retain data for 1 month and then move them to an archive storage available for 12 month?
Once you got those information, then you can move to the resources sizing activities (e.g. how many workers, collectors and how many cpu,ram, storage are required) according to this gude
https://docs.fortinet.com/document/fortisiem/6.6.5/sizing-guide/965243/fortisiem-sizing-guide
Regards
