Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
BrunoCiongoli
Collaborator
Jump to solution

Harmony endpoint logs to syslog server

Hi mates,

 

I have two questions about the "Event Forwarding" on infinity portal:

 

1- Is possible to calculate size of logs that harmony endpoint sent to syslog server before sending it? (This is to know how many disk size we have to assign to SIEM)

 

2-How often does the portal send the logs to the SIEM?

 

Thanks in advance

1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

To answer both questions, logs are sent as they are generated.
That makes it impractical to calculate how much will be sent beforehand.

View solution in original post

8 Replies
PhoneBoy
Admin
Admin

To answer both questions, logs are sent as they are generated.
That makes it impractical to calculate how much will be sent beforehand.

BrunoCiongoli
Collaborator

Thank you very much for the info! 

the_rock
Legend
Legend

Hey Bruno,

We have customers where we configured logs to be sent to siem solution and yes, Phoneboy is correct, they are sent in real time, so its almost impossible to tell what size they would be.

But, if you want a ballpark estimate, I can try figure it out for you, let me know.

Best,

Andy

0 Kudos
the_rock
Legend
Legend

Btw, I just took this from one client's environment for smart-1 cloud instance (cloud mgmt), but will try get it for harmony endpoint as well.

Best,

Andy

 

 

Screenshot_1.png

0 Kudos
the_rock
Legend
Legend

Hey Bruno,

One of my colleagues from SIEM team got back to me and let me know that on average, from client I was referring to, we get about 40 K logs a day. He can check the average log size Monday, and I can give you that info.

Best,

Andy

0 Kudos
the_rock
Legend
Legend

@BrunoCiongoli K, so found out its about 38-40 K logs a day, averaging 2 KB per log. Hope that info is somewhat useful : - )

Best,

Andy

BrunoCiongoli
Collaborator

Thank you Andy! it was so helpful for me.

the_rock
Legend
Legend

Glad we can help mate.

Best,

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events