Design for Analytics and Reporting Performance
Analytics and reporting place demands on FortiSIEM in addition to log processing. When planning the deployment consider the following:
-
The number of analysts
-
How heavily the system is used
-
Scheduled reporting requirements
Adding additional resources into the Supervisor node will help to scale GUI performance for very large deployments where there are a large number of concurrent analysts.
FortiSIEM with ClickHouse distributes queries across multiple shards. Design a solution with more shards for increased query performance.