Hi,
1. Where you're logging to.
If logs only go to the Infinity Portal cloud, the customer doesn't pay for storage, so the raw volume is largely a non issue. It becomes relevant when you forward to Syslog, CEF, or local gateway storage.
2. What you've enabled in the Log Trigger.
The defaults (URL path, URL query) are relatively lightweight. The big multipliers are HTTP headers and request body , once those are on, log size grows significantly.
Same with "All web requests (including legitimate)" vs. just detect/prevent events.
what's the use case driving this? SIEM sizing, cost modeling, retention planning?