FortiSIEM
FortiSIEM provides Security Information and Event Management (SIEM) and User and Entity Behavior Analytics (UEBA)
Andy_G
Staff
Staff
Article Id 198532

Description

Summary of Topic

This article describes how AO will enforce eps through collectors.  It will also describe the behavior and how this license will be used to limit eps collection

 

Background Information

In AO-SP mode, AccelOps collectors enforce an eps limit driven by license. AccelOps allows a burst of 110% of the license limit every 3 minutes.

A counter for the total number of received events in a 3 minute time window is maintained. Every incoming event increments the counter. Every second, a thread wakes up and checks the counter value. If the counter is smaller than 110% of the license limit (i.e. smaller than 1.1 * eps license limit * 180), then AccelOps continues collecting more events. Otherwise, events are discarded for the rest of the 3 min time window. The counter is reset at the end of the 3 minute time window.

 

Version Application

All



 
Contributors