<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Estimate data load for logging to splunk in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Estimate-data-load-for-logging-to-splunk/m-p/80794#M80816</link>
    <description>No, because a single, 10GB stream will generate less logs than, say, 1,000 users surfing the web will, even if the aggregate bandwidth they use is less than 10GB.&lt;BR /&gt;The number of concurrent connections, the exact rules they match and the level of logging for those rules (None versus Log versus Detailed versus Extended) is what will determine the log volume.&lt;BR /&gt;&lt;BR /&gt;While there is also non-user traffic, it's almost guaranteed that user traffic will generate the most logs.&lt;BR /&gt;You could probably simulate typical user traffic in the lab for one user and have it accepted on the expected rule they'd hit (e.g. with Detailed or Extended Logs) for whatever period of time you're interested in.&lt;BR /&gt;Based on the volume of logs that simulation generates, multiply by the expected number of users and...you have an estimate over that period.&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Fri, 03 Apr 2020 21:10:14 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-04-03T21:10:14Z</dc:date>
    <item>
      <title>Estimate data load for logging to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Estimate-data-load-for-logging-to-splunk/m-p/80453#M80813</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are installing and configuring NGFW for multiple sites and due to the current splunk configuration, we need to send the log from CheckPoint to a syslog server prior to the splunk environment.&lt;/P&gt;&lt;P&gt;We therefore need to estimate the logging data flowbefore the installation (all solutions to estimate the log size based on CheckPoint interface are then not applicable).&lt;/P&gt;&lt;P&gt;Is there a simple way to estimate the size of the logging flow? Based on the equipment (for example CP5800), number of users (for example 10) and the traffic going through the firewall (for example 10G/sec)?&lt;/P&gt;&lt;P&gt;Thanks for the help!&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 11:43:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Estimate-data-load-for-logging-to-splunk/m-p/80453#M80813</guid>
      <dc:creator>hutinop</dc:creator>
      <dc:date>2020-04-01T11:43:24Z</dc:date>
    </item>
    <item>
      <title>Re: Estimate data load for logging to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Estimate-data-load-for-logging-to-splunk/m-p/80685#M80814</link>
      <description>Logging is a function of three things: Traffic, blades enabled, and your precise policy configuration, all of which determine what is actually logged.&lt;BR /&gt;A "size" of appliance doesn't really tell you how much logs will be generated.&lt;BR /&gt;Are you using Log Exporter here or what's the precise configuration?&lt;BR /&gt;</description>
      <pubDate>Fri, 03 Apr 2020 00:02:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Estimate-data-load-for-logging-to-splunk/m-p/80685#M80814</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-03T00:02:03Z</dc:date>
    </item>
    <item>
      <title>Re: Estimate data load for logging to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Estimate-data-load-for-logging-to-splunk/m-p/80725#M80815</link>
      <description>&lt;P&gt;For now we are assuming that all the blades of NGFW will be active (therefore not the sandblast ones).&lt;/P&gt;&lt;P&gt;We are using the checkpoint Log Exporter to send the log to the splunk environment via a syslog server (we need the syslog server to ensure the load balancing over the 4 splunk indexers).&lt;/P&gt;&lt;P&gt;As for traffic, is it a more or less linear function? i.e. 10G/s will generate 10x more log than 1G/s?&lt;/P&gt;&lt;P&gt;Thanks for you help &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt; !&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 09:04:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Estimate-data-load-for-logging-to-splunk/m-p/80725#M80815</guid>
      <dc:creator>hutinop</dc:creator>
      <dc:date>2020-04-03T09:04:07Z</dc:date>
    </item>
    <item>
      <title>Re: Estimate data load for logging to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Estimate-data-load-for-logging-to-splunk/m-p/80794#M80816</link>
      <description>No, because a single, 10GB stream will generate less logs than, say, 1,000 users surfing the web will, even if the aggregate bandwidth they use is less than 10GB.&lt;BR /&gt;The number of concurrent connections, the exact rules they match and the level of logging for those rules (None versus Log versus Detailed versus Extended) is what will determine the log volume.&lt;BR /&gt;&lt;BR /&gt;While there is also non-user traffic, it's almost guaranteed that user traffic will generate the most logs.&lt;BR /&gt;You could probably simulate typical user traffic in the lab for one user and have it accepted on the expected rule they'd hit (e.g. with Detailed or Extended Logs) for whatever period of time you're interested in.&lt;BR /&gt;Based on the volume of logs that simulation generates, multiply by the expected number of users and...you have an estimate over that period.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 03 Apr 2020 21:10:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Estimate-data-load-for-logging-to-splunk/m-p/80794#M80816</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-03T21:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: Estimate data load for logging to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Estimate-data-load-for-logging-to-splunk/m-p/80907#M80817</link>
      <description>&lt;P&gt;thank you very much&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt; - this is valuable information.&lt;/P&gt;&lt;P&gt;Running a test to get the log size for one user presupposes that you already have the CheckPoint infrastructure, at least in a test environment. Assuming we do not, is there any chance that there is a method / estimate for let's say all blades enabled, detailed or extended log policy, 1 user surfing for 1GB traffic?&lt;/P&gt;&lt;P&gt;I understand it is difficult to estimate but we are just looking at ballpark figures.&lt;/P&gt;&lt;P&gt;Thanks again for your help!&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2020 07:36:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Estimate-data-load-for-logging-to-splunk/m-p/80907#M80817</guid>
      <dc:creator>hutinop</dc:creator>
      <dc:date>2020-04-06T07:36:19Z</dc:date>
    </item>
    <item>
      <title>Re: Estimate data load for logging to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Estimate-data-load-for-logging-to-splunk/m-p/80985#M80818</link>
      <description>Detailed versus Extended Logs can make a huge difference in log volume.&lt;BR /&gt;In any case, I personally don't have a way to test at this volume. &lt;BR /&gt;I can see if we have anything based on QA testing, but your best bet would be to engage your local office with this requirement.</description>
      <pubDate>Mon, 06 Apr 2020 14:57:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Estimate-data-load-for-logging-to-splunk/m-p/80985#M80818</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-06T14:57:16Z</dc:date>
    </item>
    <item>
      <title>Re: Estimate data load for logging to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Estimate-data-load-for-logging-to-splunk/m-p/81042#M80819</link>
      <description>What R&amp;amp;D told me was that each log record is roughly 850 bytes to 1000 bytes when exported with Log Exporter, with the average being 950.&lt;BR /&gt;&lt;BR /&gt;Since I don't have a way to test this, what I can give you is the stats from a family of four who making use of our Internet at home.&lt;BR /&gt;During the last 24 hours or so, my family of four generated about 30GB of traffic through my gateway, which generated roughly 80,000 logs...with most of the blades enabled and most (not all) things logged.&lt;BR /&gt;&lt;BR /&gt;Using these estimates--and they are just that--I would be exporting 72.5mb a day in traffic via Log Exporter.&lt;BR /&gt;However, this is based on the traffic patterns of my family over the course of one day.&lt;BR /&gt;Lots of things will impact the real numbers, as I said.</description>
      <pubDate>Mon, 06 Apr 2020 20:53:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Estimate-data-load-for-logging-to-splunk/m-p/81042#M80819</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-06T20:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: Estimate data load for logging to splunk</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Estimate-data-load-for-logging-to-splunk/m-p/81088#M80820</link>
      <description>&lt;P&gt;Many thanks!&lt;BR /&gt;We will try to set up a test as you suggested!&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 08:05:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Estimate-data-load-for-logging-to-splunk/m-p/81088#M80820</guid>
      <dc:creator>hutinop</dc:creator>
      <dc:date>2020-04-07T08:05:16Z</dc:date>
    </item>
  </channel>
</rss>

