- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Dear all
My SMS is R80.10,provide smartevent service,but it have as follow attention:
"Scale is not according to recommendation"
What does that mean?
@Jeff_Gao , taking it at face value, it looks like you are over-utilizing the SmartEvent server 20 times it's recommended capacity and capabilities.
@Jeff_Gao , please let us know the specifications of the hardware (virtual or physical, your SmartEvent is installed on.
Additionally, please specify the IOPs parameters of the storage you are using with it and if it is a standalone SmartEvent or if it is a combined with the Management server.
Without knowing this data, I can point you to this document, that should've been used for the sizing information:
https://www.checkpoint.com/downloads/products/smart-1-security-management-platform-datasheet.pdf
Look for "sustained logs" and " burst" data and compare that to the numbers you are seeing n your warning.
Then perform:
[Expert@SMS8030EA:0]# CPLogInvestigator -a -m -p
Thank you for using log investigator tool.
==============================================================
Start reading log file: /opt/CPsuite-R80.30/fw1/log/fw.log
Start reading log file: /opt/CPsuite-R80.30/fw1/log/fw.log from log 0
..
Reading log file is DONE.
Total scanned 14680 logs out of 14680 logs in file
Scanned logs dates are from 17-06-2019 00:00:00 to 17-06-2019 08:43:30
========================================
Product log statistics (Per Day):
Days of counting: 0.363542
Product name: Anti Malware Amount of logs: 547 Average: 1504
Product name: Application Control Amount of logs: 2 Average: 5
Product name: Linux OS Amount of logs: 4 Average: 11
Product name: N/A Amount of logs: 1 Average: 2
Product name: New Anti Virus Amount of logs: 14 Average: 38
Product name: Security Gateway/Management Amount of logs: 20 Average: 55
Product name: Syslog Amount of logs: 225 Average: 618
Product name: URL Filtering Amount of logs: 2 Average: 5
Product name: VPN-1 & FireWall-1 Amount of logs: 13865 Average: 38138
Total logs per day:
Date | GB | Count
2019-04-05 | 0.0003 | 6252
2019-04-06 | 0.0022 | 45242
2019-04-07 | 0.0022 | 43610
2019-04-08 | 0.0022 | 44218
2019-04-09 | 0.0023 | 45792
2019-04-10 | 0.0023 | 46500
2019-04-11 | 0.0025 | 50386
....
2019-06-17 | 0.0072 | 83864
fw.log | 0.0025 | 29360
==============================================================
Logs per minute table can be found at logPerMinute.txt
==============================================================
..and look at the "LogPerMinute" file to get an idea as to your actual consumption:
[Expert@SMS8030EA:0]# ls
logPerMinute.txt sms8030gaia
[Expert@SMS8030EA:0]# less logPerMinute.txt
@Jeff_Gao , so your VM, running Management Server with SmartEvent, except for RAM is roughly rated at 3,750 sustained logs per second:
2 SmartEvent configuration
3 In Multi-Domain configuration
This translates into 225,000 logs per minute.
Your LogsPerMinute.txt shows:
# cat logPerMinute.txt
Rounded log time: 18-06-2019 09:55; Log count: 27078
Rounded log time: 18-06-2019 09:54; Log count: 328174
Rounded log time: 18-06-2019 09:53; Log count: 280652
Rounded log time: 18-06-2019 09:52; Log count: 347959
Rounded log time: 18-06-2019 09:51; Log count: 297595
Rounded log time: 18-06-2019 09:50; Log count: 301089
Rounded log time: 18-06-2019 09:49; Log count: 303587
Rounded log time: 18-06-2019 09:48; Log count: 322227
Rounded log time: 18-06-2019 09:47; Log count: 288479
with each line except topmost one, exceeding rated parameter of the capacity you have provisioned.
Specifically, the RAM you have allocated is not even close to the specs of the hardware servers dedicated to processing same number of logs per minute.
If you want to have a chance at crunching same number of logs, see if you can match the specs of the 5150 appliance and that your storage IOPs are on the higher end of the spectrum.
Regards,
Vladimir
In a nutshell, yes. Hike it up to 64GB at least to see if the situation will improve.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY