Re: [fw-wiz] syslog and network management



On Wed, 20 Feb 2008, Darden, Patrick S. wrote:

3. Performance-wise, is there anything special needed? Not really.
It depends on the size of the network, number of devices, how much
detail you are recording, etc. What you describe is a good basis for
starting. Proably the three best things you could do would be: dual
core cpu (any decent ghz), a great NIC (or two, lots of udp bursts from
syslog), and lots of storage (you would want to keep at least 1 year in
local drive space).

if you end up doing much searching through your logs you can end up eating
a LOT more CPU then you imagine, especially as you correlate things and
end up searching for more related items at a time.

I've also found that it's faster to gzip the logs as you rotate them and
search through the compressed logs then to search through the same volume
of logs uncompressed.

what I do on my very busy servers is to put one high-rpm SCSI drive and
one (or more) large SATA drives in the box. I have syslog write to the
SCSI drive and then when I rotate the logs I save them to the slow, but
cheap SATA drive.

David Lang
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: Hardware + Exchange 2003
    ... I will put the log files on the mirrored 36gb drives, ... the logs ... > created and what the allocation unit size is. ... > recommend building the server through a process that results in a 4K ...
    (microsoft.public.exchange.setup)
  • Re: New Mailbox Store or New Storage Group?
    ... the logs and db's be on seperate spindles. ... I can only add two more drives to this server which will become the e: ... >>way to go is to create a new storage group and add a mailbox store in it. ...
    (microsoft.public.exchange.admin)
  • Re: External backup/restore - an idea - comments please
    ... After you copy off the unmirrored drives ... When I say mirrored I mean OS or drive vendor mirroring. ... SANS that did double mirroring for this kind of backup. ... Now this doesn't solve point in time backups using the logs. ...
    (comp.databases.informix)
  • Re: XPE on 2 drives with EWF
    ... Another approach you may find helpful is exploring settings pages and resources of corresponding components. ... Dr. Watson, WBEM logs, System Variables: ... possible with the two drives. ... folder to a different drive. ...
    (microsoft.public.windowsxp.embedded)
  • Re: chat logs
    ... I'm glad too se everyone helping out to find the logs and giving advice ... on how to search those teen-agers web history. ... but neither is searching for logs. ... >The Emergency Response Task Force assigned to our case asked parents to ...
    (Security-Basics)