IT Compliance & Event Log Management Software for SIEM
EventLog Analyzer - Performance Tuning
EventLog Analyzer product performs better in the supported Operating Systems. Also, the EventLog Analyzer performance depends on the speed of the hosts. The product, in addition, maintains compatibility with the server parameter.
MySQL Database Tuning
MySQL database is bundled with EventLog Analyzer. The batch/script file (startDB.bat/sh) in which the parameters need to changed is located at
Java Parameters Tuning
For RAM size exceeding 2 GB for EventLog Analyzer server, follow these guidelines to allocate more memory to Java process. This will improve overall performance of the application.
Disk Space Optimization
The role of EventLog Analyzer in your organization IT is to collect, analyze, record and preserve the logs. The analysis of the logs will detect operational issues in systems and servers within the IT environment. It finds out internal security issues and assists in confirming compliance and forensic investigation. The performance of EventLog Analyzer in your environment is determined by the following factors: the rate at which the logs are generated, the number of hosts that require monitoring and the volume of logs produced.
Hardware Requirements for EventLog Analyzer
Software Requirements for EventLog Analyzer
The basic software requirements for EventLog Analyzer to perform on your systems is listed below:
If EventLog Analyzer is installed in SuSE Linux, you need to ensure that in the mysql-ds.xml file located at
Disk Space Requirement
Quick Estimate Table
The following table focuses on the disk space and RAM size requirements of the system for installing EventLog Analyzer. This requirement is based on: the number of hosts for EventLog Analyzer to extract logs from; the rate of activities occurring per second or on per day basis.
The below mentioned data is computed by accounting 100 hosts to derive an average log size of 500 bytes.
The Method of Calculating the Required Hard Disc Space
EventLog Analyzer Disc Space scales to meet the growing collection of logs and the number of host devices configured for log collection. By default, the 'Archive' and 'Indexes' folder located at the product installation path tend to increase in size. It is advisable to calculate an estimate of the hardware requirement based on the specified criteria for a specific period of time and for 'x' number of devices. Consider the following method of calculating, considering the parameters to reach an estimate on the hard disc space requirement to run EventLog Analyzer:
Total Disc Space = Archive+Indexes + 5 GB
We can directly calculate the Archive content as below,
Archive = Average Log Size * Logs per sec per H ost * 60 * 60 * 24 * No of Days * No of Hosts Indexes = 1.3 * Average Log Size * Logs per sec per Host * 60 * 60 * 24 * No of Days * No of Hosts = 1.3 * Archive
Therefore, the Total Disc Space would be ===> ( Archive + 1.3 * Archive )/10 + 4 days of archive + 7days of Index+ 5 GB) i.e., Default Archive zip interval is 4 days and Index zip interval is 7 days.
Average Log Sizes:
EventLog Analyzer facilitates the filter option that will retain and prioritize only those logs in the database that are of corporate interest for a quick view. Rest of the logs are collected in the archive folder and are made available for viewing at any given point of time. Additionally, the filtering functionality also ensures the optimum use of hard disc. Gain an insight into the Database Filter option by accessing the link:
You may not want to apply the filtering technique to the generated logs. Regardless of the log type or severity, you may want all the logs to appear on the database as well as on the archive folder. To do so, you follow these guidelines:
Default Entry :
bin\SysEvtCol.exe -loglevel 2 -port 513 514 %*
bin\SysEvtCol.exe -loglevel 2 -filtBeforeArch 1 -port 513 514 %*
General Instructions to Control Disk Space Growth
In case of any disc space constraint, it is possible to shift the folders: Archive and Indexes to a different drive or Network Mapped Drive. To do so, you can access the options available on: Settings > Archive Settings page· A choice of locations is available for archiving and swapping the logs periodically. For instance, you can transfer the contents of the dormant archive to tape drive or high capacity storage for longer period of storage. Facility to assign separate dedicated drive(s) to archive log files in order to overcome the disk space limitation issue, is possible.
In case, the product is running in debug mode, after consulting the support personnel instruction, you should change it to default log level as soon as the support request is closed. Debug level will increase the 'log' folder growth (located under <EventLog Analyzer Home>\server\default directory).
For any other issues, please contact EventLog Analyzer Technical Support