If you log successful TLS handshakes in addition to unsuccessful TLS
handshakes, configure a larger log storage space quota () for decryption logs.
The default quota (allocation) is one percent of the device’s log storage
capacity for decryption logs and one percent for the general decryption
summary. There is no default allocation for hourly, daily, or weekly
decryption summaries.
Many factors determine the amount of storage you might need for decryption
logs and they depend on your deployment. For example, take these factors
into account:
The total combined allocation of log quotas cannot exceed 100% of the
available NGFW log resources.
You may need to experiment to find the right quota for each log category in
your particular deployment. If you only log unsuccessful handshakes, you
could start with the default or increase the allocation to two or three
percent. If you log both successful and unsuccessful handshakes, you could
start by allocating about half of the space to decryption logs that you
allocate to Traffic logs. The logs from which you take the space to allocate
to decryption logs depends on your traffic, your business, and your
monitoring requirements.