- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Dear all
My SMS is R80.10,provide smartevent service,but it have as follow attention:
"Scale is not according to recommendation"
What does that mean?
@Jeff_Gao , taking it at face value, it looks like you are over-utilizing the SmartEvent server 20 times it's recommended capacity and capabilities.
@Jeff_Gao , please let us know the specifications of the hardware (virtual or physical, your SmartEvent is installed on.
Additionally, please specify the IOPs parameters of the storage you are using with it and if it is a standalone SmartEvent or if it is a combined with the Management server.
Without knowing this data, I can point you to this document, that should've been used for the sizing information:
https://www.checkpoint.com/downloads/products/smart-1-security-management-platform-datasheet.pdf
Look for "sustained logs" and " burst" data and compare that to the numbers you are seeing n your warning.
Then perform:
[Expert@SMS8030EA:0]# CPLogInvestigator -a -m -p
Thank you for using log investigator tool.
==============================================================
Start reading log file: /opt/CPsuite-R80.30/fw1/log/fw.log
Start reading log file: /opt/CPsuite-R80.30/fw1/log/fw.log from log 0
..
Reading log file is DONE.
Total scanned 14680 logs out of 14680 logs in file
Scanned logs dates are from 17-06-2019 00:00:00 to 17-06-2019 08:43:30
========================================
Product log statistics (Per Day):
Days of counting: 0.363542
Product name: Anti Malware Amount of logs: 547 Average: 1504
Product name: Application Control Amount of logs: 2 Average: 5
Product name: Linux OS Amount of logs: 4 Average: 11
Product name: N/A Amount of logs: 1 Average: 2
Product name: New Anti Virus Amount of logs: 14 Average: 38
Product name: Security Gateway/Management Amount of logs: 20 Average: 55
Product name: Syslog Amount of logs: 225 Average: 618
Product name: URL Filtering Amount of logs: 2 Average: 5
Product name: VPN-1 & FireWall-1 Amount of logs: 13865 Average: 38138
Total logs per day:
Date | GB | Count
2019-04-05 | 0.0003 | 6252
2019-04-06 | 0.0022 | 45242
2019-04-07 | 0.0022 | 43610
2019-04-08 | 0.0022 | 44218
2019-04-09 | 0.0023 | 45792
2019-04-10 | 0.0023 | 46500
2019-04-11 | 0.0025 | 50386
....
2019-06-17 | 0.0072 | 83864
fw.log | 0.0025 | 29360
==============================================================
Logs per minute table can be found at logPerMinute.txt
==============================================================
..and look at the "LogPerMinute" file to get an idea as to your actual consumption:
[Expert@SMS8030EA:0]# ls
logPerMinute.txt sms8030gaia
[Expert@SMS8030EA:0]# less logPerMinute.txt
@Jeff_Gao , so your VM, running Management Server with SmartEvent, except for RAM is roughly rated at 3,750 sustained logs per second:
2 SmartEvent configuration
3 In Multi-Domain configuration
This translates into 225,000 logs per minute.
Your LogsPerMinute.txt shows:
# cat logPerMinute.txt
Rounded log time: 18-06-2019 09:55; Log count: 27078
Rounded log time: 18-06-2019 09:54; Log count: 328174
Rounded log time: 18-06-2019 09:53; Log count: 280652
Rounded log time: 18-06-2019 09:52; Log count: 347959
Rounded log time: 18-06-2019 09:51; Log count: 297595
Rounded log time: 18-06-2019 09:50; Log count: 301089
Rounded log time: 18-06-2019 09:49; Log count: 303587
Rounded log time: 18-06-2019 09:48; Log count: 322227
Rounded log time: 18-06-2019 09:47; Log count: 288479
with each line except topmost one, exceeding rated parameter of the capacity you have provisioned.
Specifically, the RAM you have allocated is not even close to the specs of the hardware servers dedicated to processing same number of logs per minute.
If you want to have a chance at crunching same number of logs, see if you can match the specs of the 5150 appliance and that your storage IOPs are on the higher end of the spectrum.
Regards,
Vladimir
In a nutshell, yes. Hike it up to 64GB at least to see if the situation will improve.
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY