Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ppp
New Contributor

Fortianalyzer VM vs hardware

Hi

 

What are pros and cons here? Im talking about 6-10k log/s. Which of solution would show best GUI, logview, fortiview and reporting performance?

3 REPLIES 3
ede_pfau
SuperUser
SuperUser

Hard to tell without knowing how your hypervisor hardware looks like. But I estimated...

- 100 bytes per log message

- 100 x 10.000 ~ 1 MBps traffic in

this doesn't look like it couldn't be done.

Integrating 10 k log messages per second into the DB will take some CPU, though.

Same holds true for management and reporting performance, it depends on the type and number of CPUs and size of RAM.

If you need closer right sizing advice, contact your Fortigate partner and/or a FTNT support engineer. They have experience with VM sizing.


What I really like to point out is that with a VM, you will not run into problems with future firmware compatibiliy. HW FAZ will someday tell you that the end of it's lifetime (firmware wise) is reached, and then a new appliance is due. Not so with FAZ-VM.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Debbie_FTNT

In addition to Ede's update - FortiAnalyzer VM is more scalable, so if you anticipate your logging requirements to change, you can stock up on licenses more easily for a FortiAnalyzer VM.

But as Ede also mentioned, reaching out to your Fortinet parter/sales representative would be the best option; they can assess your needs and make suggestions accordingly.

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
ppp
New Contributor

Thanks for insights. I hope we will get demo VM and will see how does it run in our virtual infrastructure.

Labels
Top Kudoed Authors