- CheckMates
- :
- Products
- :
- Harmony
- :
- Endpoint
- :
- Re: Harmony endpoint logs to syslog server
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Harmony endpoint logs to syslog server
Hi mates,
I have two questions about the "Event Forwarding" on infinity portal:
1- Is possible to calculate size of logs that harmony endpoint sent to syslog server before sending it? (This is to know how many disk size we have to assign to SIEM)
2-How often does the portal send the logs to the SIEM?
Thanks in advance
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
To answer both questions, logs are sent as they are generated.
That makes it impractical to calculate how much will be sent beforehand.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
To answer both questions, logs are sent as they are generated.
That makes it impractical to calculate how much will be sent beforehand.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you very much for the info!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey Bruno,
We have customers where we configured logs to be sent to siem solution and yes, Phoneboy is correct, they are sent in real time, so its almost impossible to tell what size they would be.
But, if you want a ballpark estimate, I can try figure it out for you, let me know.
Best,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Btw, I just took this from one client's environment for smart-1 cloud instance (cloud mgmt), but will try get it for harmony endpoint as well.
Best,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey Bruno,
One of my colleagues from SIEM team got back to me and let me know that on average, from client I was referring to, we get about 40 K logs a day. He can check the average log size Monday, and I can give you that info.
Best,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@BrunoCiongoli K, so found out its about 38-40 K logs a day, averaging 2 KB per log. Hope that info is somewhat useful : - )
Best,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you Andy! it was so helpful for me.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Glad we can help mate.
Best,
Andy
