This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

LEM Help

Howdy- 

We are evaluating LEM for offload of our Qradar system.  Qradar is a bit overloaded and upgrading it is very costly.   The security team had us spin up a demo of the solarwinds LEM product.  We put a few various devices on it and the information provided was satisfactory to the security team.

I have the spec sheet-  but I have a few questions regarding some of the Security Team's concerns.

LEM system requirements - SolarWinds Worldwide, LLC. Help and Support

1. Performance. 

     a. Can you provide a rough estimate about how many Events Per Second you are sustaining

     b. Rough specs of your system (CPU, MEMORY, ETC)

     c. Any bottlenecks

2. Stability

     a. Any concerns about stability and reliability?

You can PM me or reply back- which ever works best for you.

Thanks!

  • The "Large" deployment described in the linked document will (in our testing) support between 2000 and 4000 events per second.  Rough specifications are provided in the same doc, so I'm not sure what I can add here.  Bottlenecks for LEM tend to do with storage IOPS (LEM writes to the disk constantly in a busy environment, so poor IOPS will hurt the LEM) and memory in the virtual environment.  This is why SolarWinds recommends reserving the memory for the appliance, and treating LEM as a real-time application.

    I'll leave ito actual customers to describe their experiences with reliability and stability: SolarWinds Security Case Studies | TechValidate