TOC & Recently Viewed

Recently Viewed Topics

Log Correlation Engine Hardware Requirements

The following hardware recommendations for LCE are to be used as a general guide. Enterprise networks can vary in performance, capacity, protocols, and overall activity. Resource requirements to consider for deployments include raw network speed, the size of the network being monitored, and the configuration of the application. Processors, memory, and network cards will be heavily based on the former. Disk space requirements will vary depending on usage based on the amount and length of time data is stored on the system.

The hardware requirements for LCE change based on the number of events being processed.

Estimating Events

The following table provides the estimated average number of events from various sources.

Devices

Number of Estimated Events

1 workstation/laptop

0.5 events/sec

1 web-facing app server

20 events/sec

1 web-facing firewall/IDS/IPS

75 events/sec

1 internal application server (low volume)

5 events/sec

1 internal application server (high volume: IIS, Exchange, AD)

20 events/sec

1 internal network device

2 events/sec

To convert your event rate to bytes per day, Tenable recommends that you multiply your total events/second by 250 bytes/event and multiply by 86,400 seconds/day.

Tip:

You can use the following calculator to determine the total number of events per second as well as the bytes per day.

Workstations

Web-facing Application Servers

Web-facing Firewalls/IDS/IPS

Internal Application Servers (low volume)

Internal Application Servers (high volume: IIS, Exchange, AD)

Internal Network Devices

events/second * 250 bytes/event * 86,400 second/day = 0 bytes/day

System Specification

The following table specifies the system requirements based on the number of events the LCE server is processing.

Version Installation scenario RAM Processor Hard disk Hard disk space
5.x One LCE server with Elasticsearch processing less than 5,000 events per second 16 GB 64-bit, 8 cores, 3 GHz 10,000 to 15,000 RPM HD, or SSD of equiv. IOPS capability, in RAID 0/10 configuration

2x Licensed storage size

Note: To query an archived Elasticsearch database, it will need to be restored. The recommended hard disk space does not include optional archiving of logs that exceed the licensed limit.

One LCE server with Elasticsearch processing between 5,000 and 20,000 events per second 32 GB 64-bit, 16 cores, 3 GHz
One LCE server with Elasticsearch processing greater than 20,000 events per second 64 GB or more 64-bit, 24 cores or more, 3 GHz
Previous Versions
4.4.x through 4.8.x One LCE server processing less than 5,000 events per second 8 GB 64-bit, 8 cores, 3 GHz 10,000 to 15,000 RPM HD, or SSD of equiv. IOPS capability, in RAID 0/10 configuration

1.5x Licensed storage size

Note: Each LCE will use, on average, 1,000,000 inodes per 1TB of licensed storage size. For more information on hardware requirements for your environment, please review Log Correlation Engine 4.6 High Availability Large Scale Deployment Guide.

One LCE server processing between 5,000 and 20,000 events per second 16 GB 64-bit, 16 cores, 3 GHz
One LCE server processing greater than 20,000 events per second 32 GB or more 64-bit, 24 cores or more, 3 GHz

The LCE server requires a minimum of 20 GB of storage space to continue running and storing logs. If less than 1 GB is available, the Log Engine (lced) process will stop gracefully and refuse to store additional logs. The current system disk space is visible on the Health and Status page of the LCE interface.

Copyright 2017. Tenable Network Security, Inc. All rights reserved. Tenable Network Security, Nessus, SecurityCenter Continuous View, Passive Vulnerability Scanner, and Log Correlation Engine are registered trademarks of Tenable Network Security, Inc. All other products or services are trademarks of their respective owners.