SamurAI Collectors

What are SamurAI Collectors?

SamurAI Collectors are components used to receive and securely transport telemetry data from client environments, security controls, and cloud services to the SamurAI Platform, where it is ingested for use within the SamurAI MDR service.

Collectors act as ingestion points within the SamurAI Platform, enabling telemetry to be collected from a wide range of technologies and environments.

What do SamurAI Collectors do?

SamurAI Collectors perform the following functions:

  • Receive telemetry from security tools, infrastructure, and cloud services
  • Support multiple data collection methods depending on the integration
  • Securely transmit telemetry to the SamurAI Platform
  • Enable consistent ingestion of telemetry across different environments

Collectors act as transport mechanisms, ensuring telemetry is delivered from source systems to the SamurAI Platform for processing and analysis.

Types of SamurAI Collectors

SamurAI MDR uses different types of collectors depending on how telemetry is accessed and integrated.

Local Collector

The Local Collector is deployed within a client-controlled environment and is used to collect telemetry from systems and services that are not directly integrated with the SamurAI Platform.

It is typically used when:

  • Telemetry is generated within internal or controlled environments
  • A local ingestion point is required to collect and forward telemetry
  • Direct integration with the data source is not available

The Local Collector can be deployed on client-managed infrastructure, including virtual environments hosted on-premises or in cloud platforms such as Amazon EC2 and Microsoft Azure.

Cloud Collector

The Cloud Collector is used to collect telemetry from cloud-based services and platforms.

It is typically used when:

  • Telemetry is accessed directly from the source using methods such as APIs, cloud storage, or push-based ingestion
  • Data is stored in cloud storage or provided by SaaS platforms
  • Integration does not require a client-deployed component

The Cloud Collector retrieves or receives telemetry from cloud services and transfers it to the SamurAI Platform.

How are collectors used?

The type of collector required depends on how the telemetry is sourced:

  • Local Collector is used when a locally deployed ingestion point is required to collect and forward telemetry
  • Cloud Collector is used when telemetry can be accessed directly from cloud services, APIs, or cloud storage

In many cases, the appropriate collector is determined automatically as part of the integration configuration.

How do SamurAI Collectors fit into the platform?

SamurAI Collectors are part of the telemetry ingestion layer within the SamurAI Platform.

  • Collectors receive telemetry from source systems
  • Data is securely transferred to the SamurAI Platform
  • Telemetry is ingested, normalized, and processed for detection and response

This architecture enables consistent telemetry collection across hybrid environments, regardless of where systems are hosted.

Next steps

  • Review the Supported Integrations and associated Integration Guides to determine the required collector type. Each Integration Guide includes details on whether a Local Collector or Cloud Collector is used, and this is also shown in the SamurAI Portal during integration setup.

  • You can also work directly in the SamurAI Portal to explore and configure integrations.

To continue and for additional information for each collector type: