This section lists the system requirements for installing and working with Log360 (Distributed and Standalone editions).
Log management solutions are resource-intensive and selecting the right hardware plays a major role in ensuring optimal performance.
The following table denotes the suggested hardware requirements based on the type of flow.
| Low Flow | Normal Flow | High Flow | |
|---|---|---|---|
| Processor cores | 6 | 12 | 24 |
| RAM | 16 GB | 32 GB |
48 GB
|
| IOPS | 150 | 750 | 1500 * |
| Disk space | 1.2 TB | 3 TB * | 4 TB * |
| Network card capacity | 1 GB/s | 1 GB/s | 10 GB/s |
| CPU Architecture | 64-bit | 64-bit | 64-bit |
Use the following table to determine the type of flow for your instance.
| Log type | Size (in Bytes) | Category | Log Units | ||
|---|---|---|---|---|---|
| Low Flow (EPS) | Normal Flow (EPS) | High Flow (EPS) | |||
| Windows | 900 | Windows | 300 | 1500 | 3000 |
| Linux, HP, pfSense, Juniper | 150 | Type 1 Syslogs | 2000 | 10000 | 20000 |
| Cisco. Sonicwall, Huaweii, Netscreen, Meraki, H3C | 300 | Type 2 Syslogs | 1500 | 6000 | 12000 |
| Barracuda, Fortinet, Checkpoint | 450 | Type 3 Syslogs | 1200 | 4000 | 7000 |
| Palo Alto, Sophos, F5, Firepower, and other syslogs | 600 | Type 4 Syslogs | 800 | 2500 | 5000 |
Currently only local and remote (NAS) drives are supported by Log360 for storing live search index and archive data.
Additional note: Search indices require fast random access to the index files, which is not possible with blob storage-type data stores such as S3 and Azure Blob store.
Cluster or shared storage impact: When ELA is running on shared or cluster storage (SAN/vSAN/Shared SSD), disk performance can depend on the load from other VMs. This can cause fluctuating IOPS, higher latency, and slower search/indexing. We recommend using dedicated disks or guaranteed IOPS for stable performance. Thin provisioning should be avoided.
Log360 has been tested to support the following browsers and versions with at least a 1024x768 display resolution:
Log360 can use the following databases as its back-end database.
Bundled with the product
External databases
Please note the hardware requirements needed to configure the MS SQL database for Log360:
| RAM | CPU | IOPS | Disk space |
|---|---|---|---|
| 8GB | 6 | 300-500 | 300-500 GB |
Log360 can be installed in machines running the following operating systems and versions:
Versions requirements for Evaluation
Version requirements for Production
Windows logs
Field cannot be empty
Linux, HP, pdSense, Juniper Type 1 Syslogs
Field cannot be empty
Cisco, Sonicwall, Huaweii, Netscreen, Meraki, H3C Type 2 Syslogs
Field cannot be empty
Barracuda, Fortinet, CheckPoint Type 3 Syslogs
Field cannot be empty
Palo Alto, Sophos. F5, Firepower and Other logs Type 4 Syslogs
Field cannot be empty
Data to be stored for?
This is the raw archive data retention period.
Value cannot be '0'
Field cannot be empty
Advanced
Log metadata ( Index ) retention
Raw index retention?
Raw index takes more space and searches are faster
Raw index retention value cannot be '0'
Field cannot be empty
Archived index retention?
Archived index are zipped, it takes less space but old data will be slow to query
Field cannot be empty
CPU cores
RAM
Disk Throughput?
Disk throughput refers to the MB/s (megabytes per second) that Log360 requires to write on the disk, without negatively impacting performance.
Disk Space
Network Card Capacity
CPU Architecture