- Products
- Learn
- Local User Groups
- Partners
-
More
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
IDC Spotlight -
Uplevel The SOC
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hello Community --
The R77x Sizing guide includes mention of CPLogInvestigator that would analyze Log Server and provide tangible metric to help intelligently size a SmartEvent appliance model.
What are our options for R80.xx ?
How are customers (and resellers) to investigate log server volume -- and associated log levels -- to properly size SmartEvent solutions?
Example: customer only has "network log" enabled due to hardware limitations under current Log Server. They would like to enable "full log" with accounting (for some use-cases).
We need to first collect data for current log volume and then extrapolate to different log density.
Product mgmt must have a strategy formulated on this.
advise. -Garrett
reference:
You can add these options to a Log, Full Log, or Network Log:
SmartEvent Sizing Guide - R77.x
http://supportcontent.checkpoint.com/solutions?id=sk87263
Smart-1 R80.x Logging Capacity Performance Improvements
The doctor-log.sh script located at $RTDIR/scripts may be of assistance to you. It will analyze the logs and give you a brief output of your Current Logging and Daily Average Logging rates. It will also produce a detailed output at /tmp/sme-diag/results/detailed_diag_report.txt. Within the detailed output is the same logging rates as well as the Indexing Status and the logs based on the blade. There is a lot more data in the detailed log than what I show below. The Log Indexes total size is also within the report. Not shown here, but in my small environment I have about 11 GB of logs across 34 days. My daily average log file size is about 324 MB. From here I could do some math to determine what my log partition needs to be sized at based on what my retention time is.
Hopefully this helps you.
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY