Re: [fw-wiz] syslog and network management



On Wed, 20 Feb 2008, Darden, Patrick S. wrote:

3. Performance-wise, is there anything special needed? Not really.
It depends on the size of the network, number of devices, how much
detail you are recording, etc. What you describe is a good basis for
starting. Proably the three best things you could do would be: dual
core cpu (any decent ghz), a great NIC (or two, lots of udp bursts from
syslog), and lots of storage (you would want to keep at least 1 year in
local drive space).

if you end up doing much searching through your logs you can end up eating
a LOT more CPU then you imagine, especially as you correlate things and
end up searching for more related items at a time.

I've also found that it's faster to gzip the logs as you rotate them and
search through the compressed logs then to search through the same volume
of logs uncompressed.

what I do on my very busy servers is to put one high-rpm SCSI drive and
one (or more) large SATA drives in the box. I have syslog write to the
SCSI drive and then when I rotate the logs I save them to the slow, but
cheap SATA drive.

David Lang
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: New Mailbox Store or New Storage Group?
    ... the logs and db's be on seperate spindles. ... I can only add two more drives to this server which will become the e: ... >>way to go is to create a new storage group and add a mailbox store in it. ...
    (microsoft.public.exchange.admin)
  • Re: Hardware + Exchange 2003
    ... I will put the log files on the mirrored 36gb drives, ... the logs ... > created and what the allocation unit size is. ... > recommend building the server through a process that results in a 4K ...
    (microsoft.public.exchange.setup)
  • Re: External backup/restore - an idea - comments please
    ... After you copy off the unmirrored drives ... When I say mirrored I mean OS or drive vendor mirroring. ... SANS that did double mirroring for this kind of backup. ... Now this doesn't solve point in time backups using the logs. ...
    (comp.databases.informix)
  • Re: XPE on 2 drives with EWF
    ... Another approach you may find helpful is exploring settings pages and resources of corresponding components. ... Dr. Watson, WBEM logs, System Variables: ... possible with the two drives. ... folder to a different drive. ...
    (microsoft.public.windowsxp.embedded)
  • Optimising use of 3592 Drives
    ... I have been searching for some details on the best ways to take advantage ... performance of the drives). ... still - migration is pending) but depending on this without sufficient ... For IBM-MAIN subscribe / signoff / archive access instructions, ...
    (bit.listserv.ibm-main)