Fortinet black logo

FortiSIEM Reference Architecture Using ClickHouse

Network Infrastructure

Network Infrastructure

The Supervisor and Worker cluster should be interconnected by a data center class LAN that provides line rate, uncontended switching of at least 1 Gbps. Larger deployments should provide 10Gbps to each node to support large scale data transfer.

Collector nodes should have a connection to the main Supervisor / Worker cluster of sufficient bandwidth to meet the anticipated log volume. The Collector nodes have two features to help with traffic bursts on lower bandwidth uplink connections:

  • Local log buffering allows the Collector to temporarily store logs on the local hard drive if it cannot upload them to the Supervisor or Worker node

  • Collector upload bandwidth limiting allows the administrator to configure a maximum upload bandwidth the Collector can use to upload logs to the supervisor or worker node

Consider the following when using these features:

  • The average log ingestion rate compared to the available or configured log upload bandwidth must be such that the Collector can clear any buffered logs over time before the collector local storage becomes full. If the collector storage becomes full, then logs will be lost

  • Buffering logs will affect rule behavior. Logs will only be considered by the rule correlation engine when they are uploaded to the supervisor or worker, not when they are received by the collector

Network Infrastructure

The Supervisor and Worker cluster should be interconnected by a data center class LAN that provides line rate, uncontended switching of at least 1 Gbps. Larger deployments should provide 10Gbps to each node to support large scale data transfer.

Collector nodes should have a connection to the main Supervisor / Worker cluster of sufficient bandwidth to meet the anticipated log volume. The Collector nodes have two features to help with traffic bursts on lower bandwidth uplink connections:

  • Local log buffering allows the Collector to temporarily store logs on the local hard drive if it cannot upload them to the Supervisor or Worker node

  • Collector upload bandwidth limiting allows the administrator to configure a maximum upload bandwidth the Collector can use to upload logs to the supervisor or worker node

Consider the following when using these features:

  • The average log ingestion rate compared to the available or configured log upload bandwidth must be such that the Collector can clear any buffered logs over time before the collector local storage becomes full. If the collector storage becomes full, then logs will be lost

  • Buffering logs will affect rule behavior. Logs will only be considered by the rule correlation engine when they are uploaded to the supervisor or worker, not when they are received by the collector