Note: These recommendations can be used as a baseline for 11.4.0.0 and adjusted as needed.
Instance compute and memory utilization will vary depending on content applied, ingestion rates and number of running queries.
This topic contains the minimum GCP instance configuration settings recommended for the RSA NetWitness Platform virtual stack components.
-
Compute Engine Instance:
- Minimum instance type - n2-standard-32 is the minimum instance type required for any NetWitness Platform component image so that it can function.
- Machine type adjustments - you must adjust machine types according to your ingestion rate, content and parsers, dashboard reports, scheduled reports, investigations, and active users.
- Ingestion rates of 15,000 EPS and 1.5 Gbps were used.
- All the components were integrated.
- The Log stream includes a Log Decoder, Concentrator, and Archiver.
- The Endpoint Hybrid stream includes an Endpoint Server, Concentrator, and Log Decoder.
- Respond receives alerts from the Reporting Engine and Event Stream Analysis.
- The background load includes reports, charts, alerts, investigation, and respond.
-
Persistent Disk (Storage)
For performance recommendations, recommended storage allocation per NetWitness host, and input/output operations per second, see the "Storage Requirements" topic in the Storage Guide for RSA NetWitness
Platform 11.x.
The following table displays the specification recommendations for NetWitness GCP instances.
Virtual Log Decoder (VLC)
Compute Engine Instance | |||
---|---|---|---|
EPS | Machine Type | Virtual CPU’s | Memory |
5,000 | n2-standard-4 | 4 | 16 GB |
10,000 | n2-standard-4 | 4 | 16 GB |
15,000 | n2-standard-8 | 8 | 32 GB |
Archiver
Compute Engine Instance | |||
---|---|---|---|
EPS | Machine Type | Virtual CPU’s | Memory |
5,000 | n2-standard-4 | 4 | 16 GB |
10,000 | n2-standard-8 | 8 | 32 GB |
15,000 | n2-standard-16 | 16 | 64 GB |
Broker
Compute Engine Instance | |||
---|---|---|---|
EPS | Machine Type | Virtual CPU’s | Memory |
5,000 | n2-standard-4 | 4 | 16 GB |
10,000 | n2-standard-4 | 4 | 16 GB |
15,000 | n2-standard-4 | 4 | 16 GB |
Log Concentrator
Compute Engine Instance | |||
---|---|---|---|
EPS | Machine Type | Virtual CPU’s | Memory |
5,000 | n2-standard-8 | 8 | 32 GB |
10,000 | n2-standard-8 | 8 | 32 GB |
15,000 | n2-standard-16 | 16 | 64 GB |
Event Stream Analysis (ESA)
Compute Engine Instance | |||
---|---|---|---|
EPS | Machine Type | Virtual CPU’s | Memory |
9,000 | n2-standard-8 | 8 | 32 GB |
18,000 | n2-standard-16 | 16 | 64 GB |
30,000 | n2-standard-32 | 32 | 128 GB |
Log Decoder
Compute Engine Instance | |||
---|---|---|---|
EPS | Machine Type | Virtual CPU’s | Memory |
5,000 | n2-standard-8 | 8 | 32 GB |
10,000 | n2-standard-16 | 16 | 64 GB |
15,000 | n2-standard-32 | 32 | 128 GB |
NetWitness Endpoint Hybrid
Compute Engine Instance | |||
---|---|---|---|
Agents | Machine Type | Virtual CPU’s | Memory |
15,000 agents | n2-standard-48 | 48 | 192 GB |