Fortinet black logo

FortiSIEM Reference Architecture Using ClickHouse

Design for Analytics and Reporting Performance

Design for Analytics and Reporting Performance

Analytics and reporting place demands on FortiSIEM in addition to log processing. When planning the deployment consider the following:

  • The number of analysts

  • How heavily the system is used

  • Scheduled reporting requirements

Adding additional resources into the Supervisor node will help to scale GUI performance for very large deployments where there are a large number of concurrent analysts.

FortiSIEM with ClickHouse distributes queries across multiple shards. Design a solution with more shards for increased query performance.

Design for Analytics and Reporting Performance

Analytics and reporting place demands on FortiSIEM in addition to log processing. When planning the deployment consider the following:

  • The number of analysts

  • How heavily the system is used

  • Scheduled reporting requirements

Adding additional resources into the Supervisor node will help to scale GUI performance for very large deployments where there are a large number of concurrent analysts.

FortiSIEM with ClickHouse distributes queries across multiple shards. Design a solution with more shards for increased query performance.