Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Administering TRITON Databases > Factors that affect reporting database size
Factors that affect reporting database size
Administering TRITON Databases | Web, Data, and Email Solutions | v8.3.x
Web visits, consolidation, and full URL logging
TRITON AP-WEB and Web Filter & Security use proprietary algorithms to reduce the volume of log data in order to achieve a balance between visibility into users' web browsing activity and the size and performance of the Log Database.
*
When you enable visits, Log Server combines the individual elements that create a web page (such as graphics and advertisements) into a single log record that includes bandwidth information for all elements of the visit.
When this option is disabled, you instead log hits. In this case, a separate log record is created for each HTTP request generated to display different page elements, including graphics, advertisements, embedded videos, and so on. This creates a much larger Log Database that grows rapidly.
Disabling visits can increase the total amount of data stored in the Log Database by a factor of 2.5.
*
To further reduce the size of the database, enable log record consolidation. This combines multiple, similar Internet requests into a single log record, reducing the granularity of reporting data.
*
Enabling full URL logging can increase the size of each record by 50%.
For information about more ways to either reduce the size of the Log Database or increase the amount of data recorded, refer to:Log Database sizing guidance
Email sizing factors
Email hybrid service
The TRITON AP-EMAIL hybrid service (included with the Email Hybrid Module) drops email that comes from known bad (blacklisted) sources and blocks email with a very high spam score in the cloud before it ever reaches the email appliance. This reduces the amount of data stored in the Email Log Database for reporting by 30 MB per user per month.
Above average email traffic: recipients, quarantined messages, or spam
The sizing guidelines above are based on the following assumptions about the email traffic handled by TRITON AP-EMAIL. These assumptions are derived from the average email traffic pattern of Forcepoint customers over time.
*
*
*
*
Note that TRITON AP-EMAIL counts the number of recipients for each message rather than the number of messages sent. Each recipient is counted as a transaction.
If the pattern of email traffic in your organization exceeds these averages, your storage capacity will vary.
Data sizing factors
Number of discovery incidents
TRITON AP-DATA limits the number of discovery incidents that can be stored in the Data Incident and Configuration Database in order to prevent improperly configured discovery policies from flooding the database. By default this limit is set to 1 million incidents. If you are using SQL Server Express, you should reduce this number to 250,000.
To do this:
1.
2.
Select the Data tab.
3.
Select Settings > General > Reporting.
4.
Select the Discovery tab.
5.
Refer to "Setting preferences for discovery incidents" in the TRITON AP-DATA Help for more information.
 
Note 
Rate of network and endpoint incidents
The rate of network and endpoint incidents detected varies widely across Forcepoint customers. The sizing guidelines above are based on an average incident rate of 1 per user every 10 days (an incident is a policy violation). For best practice, periodically review the actual incident rate in the database to gauge how closely your environment matches this average, and then adjust your database storage requirements based on the actual data in your environment.
Do this by examining the Incident Trends report found in the Data module of TRITON Manager under Main > Reporting.
 
Note 
The TRITON AP-DATA database stores data in partitions per each calendar quarter. You can have 1 active partition for the current quarter.
If you are using Microsoft SQL Server Standard or Enterprise for your TRITON database, you can have up to 8 online partitions (approximately 2 years), but if you are using SQL Server Express, you can have only 4 (approximately 1 year). (Online partitions are partitions that can be used to show reports and log data).
For both databases, you can have up to 12 archived partitions representing 3 years of records, and 4 restored partitions (1 year).
 
Refer to "Incident partitions" in the TRITON AP-DATA Help for more information on archiving. For instructions on setting the maximum disk space allowed for the incident archive, refer to "Configuring the incident archive".
Size of user directory import
To support user-based policy and reporting, TRITON AP-DATA imports entries from your user directory—such as Active Directory or Domino—into the Configuration Database. Depending on the size and design of your user directory, this can result in database space being consumed by entries that are not needed by TRITON AP-DATA. To reduce the number of imported user directory entries:
*
*
To configure user directory settings:
1.
2.
Select the Data tab.
3.
Select Settings > General > User Directories.
4.
5.
6.
Refer to the "Adding a new user directory server" section in the TRITON AP-DATA Help for information on configuring these settings.

Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Administering TRITON Databases > Factors that affect reporting database size
Copyright 2016 Forcepoint LLC. All rights reserved.