Upgrade Collectors
30 Questions
2 Views

Choose a study mode

Play Quiz
Study Flashcards
Spaced Repetition
Chat to lesson

Podcast

Play an AI-generated podcast conversation about this lesson

Questions and Answers

Which page should you navigate to in the FortiSIEM GUI to upgrade a collector?

  • Install Image page
  • Download Image page
  • Upgrade Collector page
  • Collector Health page (correct)
  • What action should you select for a collector upgrade in the FortiSIEM GUI?

  • Install Image (correct)
  • Download Image
  • Collector Health
  • Upgrade Collector
  • How does FortiSIEM calculate EPS (Events Per Second)?

  • By dividing the total number of events received over a three-minute period by 60
  • By counting the total number of events received over a three-minute period
  • By counting the total number of events received over a one-minute period
  • By dividing the total number of events received over a three-minute period by 180 (correct)
  • What is the purpose of guaranteed EPS in FortiSIEM?

    <p>To ensure that the collector can always process events at a certain rate</p> Signup and view all the answers

    Where do you define the guaranteed EPS for a collector in FortiSIEM?

    <p>Collector configuration process</p> Signup and view all the answers

    Are UEBA events counted towards EPS in FortiSIEM?

    <p>No</p> Signup and view all the answers

    What does EPS stand for in FortiSIEM?

    <p>Events Per Second</p> Signup and view all the answers

    How long is the time period over which FortiSIEM calculates EPS?

    <p>Three minutes</p> Signup and view all the answers

    What should you click to download the collector upgrade image in FortiSIEM?

    <p>Download Image</p> Signup and view all the answers

    Who instructs the collector to upgrade itself in FortiSIEM?

    <p>Service provider administrator</p> Signup and view all the answers

    Which metric does each collector periodically report to the supervisor?

    <p>Incoming EPS</p> Signup and view all the answers

    What happens if the incoming EPS is greater than the guaranteed EPS?

    <p>Events are dropped</p> Signup and view all the answers

    What is EPS bursting in FortiSIEM?

    <p>A mechanism to allow bursting above the purchased EPS</p> Signup and view all the answers

    What is the maximum EPS bursting allowed in FortiSIEM?

    <p>Five times the licensed EPS</p> Signup and view all the answers

    How does FortiSIEM calculate the initial system EPS?

    <p>Licensed value × 180 seconds + 10% Buffer</p> Signup and view all the answers

    What is the purpose of the 10% buffer in the initial system EPS calculation?

    <p>To account for fluctuations in EPS</p> Signup and view all the answers

    How does FortiSIEM calculate the unused EPS?

    <p>Sum of positive differences of allocated EPS and incoming EPS over all nodes</p> Signup and view all the answers

    What can FortiSIEM do with the accumulated unused EPS?

    <p>Use it for bursting during attacks or event surge periods</p> Signup and view all the answers

    What is the requirement to benefit from EPS bursting in FortiSIEM?

    <p>Enough computational power and storage</p> Signup and view all the answers

    What should be provisioned to handle potential event surges in FortiSIEM?

    <p>Five times the licensed EPS</p> Signup and view all the answers

    Which metric does each collector periodically report to the supervisor?

    <p>Incoming EPS</p> Signup and view all the answers

    Which feature helps customers avoid dropped events when incoming EPS is greater than guaranteed EPS?

    <p>EPS bursting</p> Signup and view all the answers

    What is EPS bursting in FortiSIEM?

    <p>A mechanism to accumulate unused EPS for bursting during attacks</p> Signup and view all the answers

    What is the maximum EPS bursting allowed in FortiSIEM?

    <p>5 times the licensed EPS</p> Signup and view all the answers

    How is the initial system EPS calculated in FortiSIEM?

    <p>Licensed value = license × 180 seconds + 10% Buffer</p> Signup and view all the answers

    What is the allocated EPS for a three-minute duration for a 520 EPS license in FortiSIEM?

    <p>102,960</p> Signup and view all the answers

    What does FortiSIEM use to keep track of unused EPS?

    <p>Positive differences of allocated EPS and incoming EPS over all nodes</p> Signup and view all the answers

    What can FortiSIEM use unused EPS for?

    <p>Bursting during attacks or event surge periods</p> Signup and view all the answers

    What should the system be provisioned with to benefit from EPS bursting in FortiSIEM?

    <p>Additional computational power and storage</p> Signup and view all the answers

    What is the end result of unused EPS over the course of a day in FortiSIEM?

    <p>Unused EPS accumulation</p> Signup and view all the answers

    Study Notes

    Upgrading a Collector in FortiSIEM

    • To upgrade a collector, navigate to the Collectors page in the FortiSIEM GUI.
    • Select the Upgrade action for a collector upgrade in the FortiSIEM GUI.

    EPS (Events Per Second) Calculation

    • FortiSIEM calculates EPS as the average number of events received per second over a 1-minute period.
    • EPS stands for Events Per Second in FortiSIEM.

    Guaranteed EPS

    • The purpose of guaranteed EPS is to ensure that a collector can handle a certain number of events per second without dropping them.
    • Guaranteed EPS is defined for a collector in the Collectors page in the FortiSIEM GUI.
    • UEBA events are counted towards EPS in FortiSIEM.

    EPS Bursting

    • If the incoming EPS is greater than the guaranteed EPS, FortiSIEM allows for EPS bursting, which temporarily accommodates the surge in events.
    • EPS bursting is a feature that helps customers avoid dropped events when incoming EPS is greater than guaranteed EPS.
    • The maximum EPS bursting allowed in FortiSIEM is 3 times the guaranteed EPS.

    EPS Calculation and Unused EPS

    • The initial system EPS is calculated as the total licensed EPS multiplied by 0.9, minus the allocated EPS for UEBA.
    • A 10% buffer is added to the initial system EPS calculation to account for fluctuations.
    • Unused EPS is the difference between the guaranteed EPS and the actual EPS.
    • FortiSIEM uses a token bucket to keep track of unused EPS.
    • Unused EPS can be accumulated and used to handle potential event surges.
    • At the end of a day, unused EPS is reset to zero.

    Provisioning and Benefits

    • To benefit from EPS bursting, the system should be provisioned with sufficient resources.
    • The system should be provisioned to handle potential event surges in FortiSIEM.

    Studying That Suits You

    Use AI to generate personalized quizzes and flashcards to suit your learning preferences.

    Quiz Team

    Description

    Test your knowledge on upgrading collectors one by one with this quiz. Learn how to download and install images, navigate the FortiSIEM GUI, and select the collector for upgrade. Upgrade your skills now!

    More Like This

    Use Quizgecko on...
    Browser
    Browser