IPS live log - 8 Minutes to get logs

Dear All,

log viewer is still a pain for me. All the time I switch from Firewall log to Application or IPS, I need to wait 8 minutes to get results.

Community: are you experiencing the same?

Merry Christmas to all.

Regards

Parents Reply Children
  • Hello Luk,

    what type of hard drive does have your HW appliance? 

    A similar behavior was observed with the hardware appliance in the case of conventional rotary disks, typically 2.5 "notebook hard drives with 5400 rpm. All Sophos HW appliances have SSDs (only XG86 has 16GB eMMC), so I would assume that developers assume they all use SSDs only. So the developers (in my opinion) do not really try to optimize disk operations during v18 development. And this behavior can be a consequence. 

    I have two pairs of 2.5 "classic 500GB and 1 TB drives on my ESXi hypervisor, and the transition from firewall logs to IPS or application logs is really about one or two minutes for these drives. In the office now for v18 EAP I use XG210 (which has SSD) and there is a transition between the logs in seconds. 

    I don't know if my experience help you solve the problem.
     
    Regards
    alda

     

  • Thanks Alda. I will perform a test on an ssd drive and let the community know.

  • Hi Community,

    this afternoon I found the time to install an SSD drive and the live log now is responsive. Still updating a firewall rule requires 14 seconds but live logs now work smoothly.

    Thanks