Hello,
Supposed you have the QRadar SIEM in the distributed configuration as follow (in the same subnet).
All in M6 xx29 appliances. (40K EPS and 2.4MM FPM)
Console x 1
Event Processor x 3
Data Nodes for the Event Processor x 3
Flow Processor x 1
Data Node for the Flow Processor x 1
App Host x 1
Suppose one of the log source type is dedicated to send all the logs to a single Event Processor and it might be maxing out the system limitation of 40K EPS. Is it possible to replace that EP with M6 xx48 (80K EPS, 3.6MM FPM) and keep the existing M6 xx29 data node (and then convert the existing EP M6 xx29 to use it as data node)?
The final configuration would look like this:
Console (M6, xx29)
EP1 (M6, xx29), Data Node1 (M6, xx29)
EP2 (M6, xx29), Data Node2 (M6, xx29)
EP3 (M6, xx48), Data Node3a (M6, xx29), Data Node3b (M6, xx29)
FP1 (M6, xx29), Data Node4 (M6, xx29)
AppHost (M6, xx29)
Any thoughts about the proposed configuration?
There is a KB article about using a load balancer before the EP and I'm trying to avoid adding that tier.
Thanks.
-nelson
------------------------------
nelson lee
------------------------------