(On-premise FortiAnalyzers) Estimating average log volume
For on-premise FortiAnalyzer deployments, you must estimate the average log volume you plan to send to SOCaaS. This estimate should include the average logs per second from all entitled and onboarded devices. If you anticipate adding more devices in the future, please factor those devices into your estimate. Your input is crucial for planning and ensuring the efficient operation of SOC services.
Within FortiAnalyzer's Device Manager, calculate the cumulative average log rates for all entitled SOCaaS devices and devices scheduled for onboarding, found in the Average Log Rate column.
For example: Calculate the average log rate as (59 + 1 + 8 + 5 + 1) / 5 = 14.8
logs per second.