Hi Denis,
Thanks a lot for your reply.
Let me give a bit more details. We are not planning to combine multiple Detection server roles on a single server, but run them on an individual nodes. Thus a single Enforce platform would combine Mail, Web and Discover Detection servers, each running a single detection server role.
Currently, our Mail monitoring and Web prevent instances generate about ~3000 incidents per day. Both Enforces do not appear to be overloaded. I am about to do a detailed performance analysis to see how "hot" they are running in terms of disk, memory and CPU utilization. Also, we are on ver 10.5 on one instance and 11.1 on other, both are Windows. The plan is to upgrade to 12.5 on Linux. We groom incidents older than 60 days on both incidents, incidents information is transferred internally for the triage and followup. We have the same reviewers team for Web, Mail and Discover.
Having a single Enforce platform would save a lot of management overhead to maintain two separate instances: single custom attributes plug-in, EDMs, grooming, Reporting integration, etc...
Are there any specific performance considerations should we be concerned with? Any specific performance counters to collect to assess the feasibility of joining two instances in one without performance degradation?
Thanks!
Alex