I'm evaluating secure web gateway solutions for a distributed SaaS platform with approximately 2,500 developer and support endpoints. A key requirement is centralized, multi-tenant logging for security event analysis and compliance reporting across several distinct business units.
iboss is on our shortlist, and their cloud architecture seems to fit the multi-tenancy model. However, their datasheets and sales engineering conversations only provide theoretical maximums for log throughput. I need to understand real-world, sustained performance under load.
Specifically, has anyone deployed iboss in a similar multi-tenant SaaS environment? I'm looking for concrete data points on:
* Actual sustained log volume (e.g., GB/day per 1,000 users) sent to a SIEM like Splunk or Azure Sentinel.
* The impact on throughput when detailed inspection policies (like SSL decryption for specific tenants) are enabled.
* Any observable latency or aggregation delays in log delivery under peak concurrent user loads.
Our preliminary TCO model is sensitive to log management costs, so real throughput numbers are critical for accurate sizing and cost projection. Anecdotal feedback on log formatting and tenant isolation in the reporting interface would also be valuable.
- Mark
independent eye