20 Questions
Which node calculates the unused events and sends the value to the central decision-making engine?
Supervisor
What is the total incoming EPS from the three collectors in the example?
175
What is the total unused events in the example?
71,460
What is the formula to calculate the total number of allowed events for the next three-minute interval?
licensed EPS + unused reservoir + 10% buffer
What is the licensed EPS in the example?
520
What is the total number of allowed events for the next three-minute interval in the example?
191,862
When does the process of building the EPS reservoir start over for the next day?
Every day at midnight
What is the restriction on the number of events that can be carried over to the next day at midnight?
50%
What is the EPS reservoir used for in FortiSIEM?
To store events during event bursts
What is the purpose of the 10% buffer in the formula to calculate the total number of allowed events?
To increase the number of allowed events
FortiSIEM can use events in the EPS reservoir if the system suddenly needs to process more than the license.
The system will automatically allocate more EPS from the reservoir
In the phoenix.log file, you can see the licensed, allowed, used, and unused (reservoir) values every three minutes.
On the Usage page of the FortiSIEM GUI
What does the supervisor node in FortiSIEM do?
It communicates EPS values to every node
What features are supported by the FortiSIEM Windows agent?
All features by default
What is the purpose of the auditd daemon on Linux?
To write audit records to the disk
What happens to the allowed events and unused reservoir values in the phoenix.log file?
They keep increasing
What is the supervisor node's role in FortiSIEM agent management?
To manage FortiSIEM Windows and Linux agents
How are logs collected by the Linux agent delivered to FortiSIEM?
Over HTTPS
What is the purpose of the EPS reservoir in FortiSIEM?
To provide additional EPS when needed
What types of nodes are there in a FortiSIEM deployment?
Supervisor, worker, and collector nodes
Test your knowledge of unused events in event processing systems with this quiz. Learn about how incoming EPS is calculated and how to determine the number of unused events.
Make Your Own Quizzes and Flashcards
Convert your notes into interactive study material.
Get started for free