- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Per device Log limits on FAZ Cloud
- Labels:
-
FortiAnalyzer
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you are talking about the capacity of the FAZ cloud, you can refer the following formula:
HDD=LR*(RA/5+3*RR)*1.2
Where:
HDD - Approximate required total disk/quota size [GB]
LR - Average log rate [GB/day] - Take the average of the weekly log rate statistic under System Settings -> Dashboard -> "License Information" widget -> GB/Day -> Details
RA - Retention period for archive/raw logs [days]
RR - Retention period for reporting/analysis [days]
"5" - When the raw logs are archived, their file size is reduced approx 5-8 times. 5 is a bit conservative and can be replaced with up to 8 for less strict retention policies
"3" - Multiplier - when the raw logs are inserted, the SQL DB files are approximately 3 times bigger than the original log size
"1.2" - 20% extra, as the disk space, can't be completely utilized. There is some space reserved for cache, temporary tables, etc..
https://community.fortinet.com/t5/FortiAnalyzer/Technical-Tip-How-to-estimate-disk-space-needed-for-...
You can also add the below chart to the FortiGate to get information on logs sent daily:
Vishal
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Vishal - good info on the sizing tool and the logging widget on the gate.
But is there a way to monitor the log usage of each gate on the Cloud FAZ dashboard ? Would be nice to have a widget to monitor so that we can easily determine if an upgrade pack is required. Tom
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is entirely dependent on the device you have, what you're logging (All sessions vs UTM only - I recommend all, because inevitably someone is going to ask for what XYZ123 is doing), and the amount of traffic transiting the FortiGate. This is very much a "it depends" answer.
