Forum Discussion
Azure ATP network traffic
Hi Khaled,
The amount of data sent to Azure ATP is dependent on the amount of traffic your Domain Controllers receive. Typically, after we parse the traffic, we send only 1-3% of the total traffic to the service for processing.
In terms of logs, these will be held on the DC which is running the Sensor and again the size will depend on how busy your environment is. We recommend that 10GB of free space is available for Sensor logs.
Let us know if you have any further questions.
Astrid McClean Hi Astrid,
Can you tell me if the capacity information "we send only 1-3% of the total traffic to the service for processing." is current?
If so, would I use the network performance data captured in the capacity planning tool?
https://docs.microsoft.com/en-us/azure-advanced-threat-protection/atp-capacity-planning
Would I use 1-3% of Max Packet /secs column?
Thank you
- Dimitry IzotovOct 28, 2020Brass Contributor
Astrid McClean would love to know the answer to the question above as well.