Manager Scalability and Performance

The Manager is designed to scale from small deployments (1–25 Sensors) to large enterprise deployments (100–200 Sensors).

  • Event Ingestion: All Sensors log to local Unix socket → Sensor adapter → message queue.

  • Streaming Analytics: Analytics engine consumes message queue and performs real-time behavioral analysis.

  • Storage Layer: Hot data in full text indexed storage(recent events, fast search); warm/cold data in columnar database storage(long-term retention, cost-optimized analytics).

  • Manager Sizing:

Manager Type

Sensors supported

CPU Cores

RAM

Storage (RAID 10 NVMe)

Manager STD

Up to 25

32–64

512 GB

19.2 TB

Manager XL

100–500

96–192

1–4 TB

76.8+ TB

  • Horizontal scaling via additional Manager nodes.