Fortinet white logo
Fortinet white logo
7.4.0

Log rate

Log rate

Logs per second (LPS): Average number of logs per second generated in a 24-hour period that a FortiAnalyzer unit will have to sustain.

The FortiAnalyzer datasheet and FortiAnalyzer BigData datasheet provide the maximum constant log message rate that each FortiAnalyzer platform can maintain for minimum 48 hours without system performance degradation.

For existing deployments, LPS can be obtained by querying devices already deployed. For new deployments (greenfield), LPS can be estimated from either sessions/sec rate or number of users per site as described below.

To estimate LPS from sessions/sec rate:

Generally, the amount of traffic logs per second is equal to the amount of sessions per second.

If additional security features are enabled, the logs generated from each feature must be added to the total according to the table below:

Log Type

% Traffic log

Antivirus

5%

IPS

5%

Application Control

20%

Web Filtering

20%

DNS

5%

Example:

Site A generates 1500 sessions/sec, and it has Antivirus, IPS, and Application Control features enabled.

Traffic log/sec = Sessions/sec

Estimated LPS:

  • Traffic (1500) + Antivirus% (75) + IPS% (75) + Application Control% (300) = Total logs/sec (1950)

To estimate LPS from number of users:

The LPS can be obtained from:

  • Total number of users per site

  • % of active users per day (use 50% as baseline)

Each user generates an average of 0.66 traffic logs/sec, and security features enabled must be added to the total according to the table below:

Log Type

% Traffic log

Antivirus

5%

IPS

5%

Application Control

20%

Web Filtering

20%

DNS

5%

Example:

Site A has 100 users in total, and 50% are active per day. The following security features are enabled: Antivirus, Web Filtering, and DNS.

Estimated % log per user:

  • Traffic log (0.66) + Antivirus% (0.033) + Web Filtering% (0.132) + DNS% (0.033) = 0.858

Estimated LPS:

  • Total users (100) * % active users (0.5) * Estimated % log per user (0.858) = 42.9

Note

Important notes

  • LPS estimated with either sessions/sec or number of users is a gross estimate in order to choose the most accurate platform for your needs. Real numbers may differ; therefore, trends should be monitored when in production.

  • Specific functionality, such as SD-WAN, can increase the overall log rate by 5-10% based on the logging and monitoring configuration in place.

  • A projected log volume in one to three years must be taken into account.

Log rate

Log rate

Logs per second (LPS): Average number of logs per second generated in a 24-hour period that a FortiAnalyzer unit will have to sustain.

The FortiAnalyzer datasheet and FortiAnalyzer BigData datasheet provide the maximum constant log message rate that each FortiAnalyzer platform can maintain for minimum 48 hours without system performance degradation.

For existing deployments, LPS can be obtained by querying devices already deployed. For new deployments (greenfield), LPS can be estimated from either sessions/sec rate or number of users per site as described below.

To estimate LPS from sessions/sec rate:

Generally, the amount of traffic logs per second is equal to the amount of sessions per second.

If additional security features are enabled, the logs generated from each feature must be added to the total according to the table below:

Log Type

% Traffic log

Antivirus

5%

IPS

5%

Application Control

20%

Web Filtering

20%

DNS

5%

Example:

Site A generates 1500 sessions/sec, and it has Antivirus, IPS, and Application Control features enabled.

Traffic log/sec = Sessions/sec

Estimated LPS:

  • Traffic (1500) + Antivirus% (75) + IPS% (75) + Application Control% (300) = Total logs/sec (1950)

To estimate LPS from number of users:

The LPS can be obtained from:

  • Total number of users per site

  • % of active users per day (use 50% as baseline)

Each user generates an average of 0.66 traffic logs/sec, and security features enabled must be added to the total according to the table below:

Log Type

% Traffic log

Antivirus

5%

IPS

5%

Application Control

20%

Web Filtering

20%

DNS

5%

Example:

Site A has 100 users in total, and 50% are active per day. The following security features are enabled: Antivirus, Web Filtering, and DNS.

Estimated % log per user:

  • Traffic log (0.66) + Antivirus% (0.033) + Web Filtering% (0.132) + DNS% (0.033) = 0.858

Estimated LPS:

  • Total users (100) * % active users (0.5) * Estimated % log per user (0.858) = 42.9

Note

Important notes

  • LPS estimated with either sessions/sec or number of users is a gross estimate in order to choose the most accurate platform for your needs. Real numbers may differ; therefore, trends should be monitored when in production.

  • Specific functionality, such as SD-WAN, can increase the overall log rate by 5-10% based on the logging and monitoring configuration in place.

  • A projected log volume in one to three years must be taken into account.