This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Discussions
  • NetWitness Community
  • Discussions
  • Sizing VM Azure
  • Options
    • Subscribe to RSS Feed
    • Mark Topic as New
    • Mark Topic as Read
    • Float this Topic for Current User
    • Bookmark
    • Subscribe
    • Mute
    • Printer Friendly Page

Sizing VM Azure

andre.oliveira
andre.oliveira New Contributor
New Contributor
Options
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

‎2020-07-15 11:22 AM

I have a VM deployment scenario for logs and packets in Azure. I'm not able to design a scenario well to reflect on the correct implementation of this machine in Azure. If anyone can help me get an idea, I'd appreciate it.

 

  • Scenario for Logs:
    • VM Log Hybrid
    • Maximum 1000 EPS (or 50GB/day)
    • Maximum retention time of 3 days (raw data) and 7 days (metada)
    • How much will I need disk, memory and cpu?
    • What better family for this implementation (BS2, D4S, E4S, et.al.....)?

 

  • Scenario for Network (still in preview):
    • VM Network Hybrid or VM Network (Decoder and Concentrator)
    • Maximum retention time of 3 days
    • How much will I need disk, memory and cpu?
    • What better family for this implementation?
    • Considering this 60% retention and utilization time, how much maximum traffic per day can I support?

 

By way of example, I came up with the following drawing

Function

Memory

Disk

IOPS

Processor

Network

Network Decoder

16GB

3,95 TB

(SSD/SAS/HDD)

200

(50 read / 150 write)

4 vCPUs

x1 vNIC Managed Mode

x1 vNIC Promiscue Mode

Network Concentrator

16GB

2,25 TB (SSD)

3.120

(150 read / 2970 write)

4 vCPUs

x1 vNIC Managed Mode

Log Hybrid

32GB

2,0 TB (SSD/SAS/HDD)

3.350

(250 read / 3100 write)

4 vCPUs

x1 vNIC Managed Mode

 

What do you think of this sizing plan? In Azure, view this families:

  • Net Decoder: D4s_v3 - 4vCPU, 16GB RAM, 6400 IOPS - S50 (4TB disk - 500 IOPS)
  • Net Concentrator: D4s_v3 - 4vCPU, 16GB RAM, 6400 IOPS - P40 (2TB disk - 7500 IOPS)
  • Log Hybrid: E4s_v3 - 4vCPU, 32GB RAM, 6400 IOPS - P40 (2TB disk - 7500 IOPS)

 

 

#azure‌ #netwitness azure‌ #microsoft azure‌

Labels:
  • Labels:
  • RSA NetWitness Endpoint
  • azure
  • azure deploy
  • azure deployment
  • Community Thread
  • Discussion
  • ECAT
  • EDR
  • Endpoint
  • Forum Thread
  • log hybrid
  • log hybrid azure
  • microsoft azure
  • NetWitness
  • netwitness azure
  • network hybrid
  • network hybrid azure
  • NWE
  • RSA NetWitness Endpoint
  • RSA NetWitness Platform
0 Likes
Share
Reply
  • All forum topics
  • Previous Topic
  • Next Topic
0 REPLIES 0
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.