<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic EPS Count in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/EPS-Count/m-p/7375#M100105</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;How to check EPS (events per second) count on the Management Server (R80.10)?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 11 Oct 2017 13:32:52 GMT</pubDate>
    <dc:creator>JAYARAM_P_M1</dc:creator>
    <dc:date>2017-10-11T13:32:52Z</dc:date>
    <item>
      <title>EPS Count</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/EPS-Count/m-p/7375#M100105</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;How to check EPS (events per second) count on the Management Server (R80.10)?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Oct 2017 13:32:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/EPS-Count/m-p/7375#M100105</guid>
      <dc:creator>JAYARAM_P_M1</dc:creator>
      <dc:date>2017-10-11T13:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: EPS Count</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/EPS-Count/m-p/7376#M100106</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you mean events as defined by SmartEvent or something else?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Oct 2017 17:02:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/EPS-Count/m-p/7376#M100106</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-10-11T17:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: EPS Count</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/EPS-Count/m-p/7377#M100107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, the events are defined by Smartevent but need to know about how the events count can be checked with the use of CPLogInvestigator?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Oct 2017 03:25:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/EPS-Count/m-p/7377#M100107</guid>
      <dc:creator>JAYARAM_P_M1</dc:creator>
      <dc:date>2017-10-12T03:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: EPS Count</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/EPS-Count/m-p/7378#M100108</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess I have to ask the question: what’s the purpose behind the question?&lt;/P&gt;&lt;P&gt;Are you trying to size an appliance or is there some other reason?&lt;/P&gt;&lt;P&gt;A sizing tool for this purpose is planned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CPLogInvestigator will tell you how many logs a given server has.&lt;/P&gt;&lt;P&gt;Non-firewall logs generally are already summarized (to an extent) and could be considered events on their own.&lt;/P&gt;&lt;P&gt;Firewall logs take the most work to “summarize” to events and the volume of logs that turn into events can vary.&lt;/P&gt;&lt;P&gt;I’ll have to see if I can find the estimations I used for this exercise previously.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Oct 2017 14:35:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/EPS-Count/m-p/7378#M100108</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-10-12T14:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: EPS Count</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/EPS-Count/m-p/7379#M100109</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Oct 2017 18:16:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/EPS-Count/m-p/7379#M100109</guid>
      <dc:creator>JAYARAM_P_M1</dc:creator>
      <dc:date>2017-10-30T18:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: EPS Count</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/EPS-Count/m-p/7380#M100110</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;At least based on a couple of years ago, roughly 13% of raw log entries become events.&lt;/P&gt;&lt;P&gt;That number will be highly dependent on your environment of course,&amp;nbsp;and whether or not you're doing session-based logging in R80.x.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Oct 2017 04:19:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/EPS-Count/m-p/7380#M100110</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-10-31T04:19:07Z</dc:date>
    </item>
    <item>
      <title>Re: EPS Count</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/EPS-Count/m-p/7381#M100111</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also try these two commands for logging rate:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;cpstat -f indexer mg&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Total Read Logs: 10184191882&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total Updates and Logs Indexed: 10184191874&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total Read Logs Errors: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total Updates and Logs Indexed Errors: 17827&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Updates and Logs Indexed Rate: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Read Logs Rate: 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Updates and Logs Indexed Rate (10min): 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Read Logs Rate (10min): 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Updates and Logs Indexed Rate (60min): 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Read Logs Rate (60min): 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Updates and Logs Indexed Rate Peak: 7908&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Read Logs Rate Peak: 8004&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Read Logs Delay: 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;cpstat -f log_server mg&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Log Receive Rate: 9266&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Log Receive Rate Peak: 24748&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Log Receive Rate Last 10 Minutes: 9386&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Log Receive Rate Last Hour: 9536&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; now available via &lt;A href="http://maxpowerfirewalls.com" target="_blank"&gt;http://maxpowerfirewalls.com&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Oct 2017 11:53:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/EPS-Count/m-p/7381#M100111</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-10-31T11:53:23Z</dc:date>
    </item>
    <item>
      <title>Re: EPS Count</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/EPS-Count/m-p/7382#M100112</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With regards to using &lt;STRONG&gt;cpstat mg -f log_server&lt;/STRONG&gt; output, is the:&lt;/P&gt;&lt;P&gt;1. Log Receive Rate a per second statistic?&lt;/P&gt;&lt;P&gt;2. and given that question 1 is true, is the Log Receive Rate Peak then the highest amount of logs that was received in one second at some point in time by the Management server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Breyten&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Mar 2018 15:21:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/EPS-Count/m-p/7382#M100112</guid>
      <dc:creator>Breyten_Borman</dc:creator>
      <dc:date>2018-03-14T15:21:45Z</dc:date>
    </item>
  </channel>
</rss>

