This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

SamurAI Collectors

What are SamurAI Collectors?

SamurAI Collectors are components used to receive and securely transport telemetry data from client environments, security controls, and cloud services to the SamurAI Platform, where it is ingested for use within the SamurAI MDR service.

Collectors act as ingestion points within the SamurAI Platform, enabling telemetry to be collected from a wide range of technologies and environments.

What do SamurAI Collectors do?

SamurAI Collectors perform the following functions:

  • Receive telemetry from security tools, infrastructure, and cloud services
  • Support multiple data collection methods depending on the integration
  • Securely transmit telemetry to the SamurAI Platform
  • Enable consistent ingestion of telemetry across different environments

Collectors act as transport mechanisms, ensuring telemetry is delivered from source systems to the SamurAI Platform for processing and analysis.

Types of SamurAI Collectors

SamurAI MDR uses different types of collectors depending on how telemetry is accessed and integrated.

Local Collector

The Local Collector is deployed within a client-controlled environment and is used to collect telemetry from systems and services that are not directly integrated with the SamurAI Platform.

It is typically used when:

  • Telemetry is generated within internal or controlled environments
  • A local ingestion point is required to collect and forward telemetry
  • Direct integration with the data source is not available

The Local Collector can be deployed on client-managed infrastructure, including virtual environments hosted on-premises or in cloud platforms such as Amazon EC2 and Microsoft Azure.

Cloud Collector

The Cloud Collector is used to collect telemetry from cloud-based services and platforms.

It is typically used when:

  • Telemetry is accessed directly from the source using methods such as APIs, cloud storage, or push-based ingestion
  • Data is stored in cloud storage or provided by SaaS platforms
  • Integration does not require a client-deployed component

The Cloud Collector retrieves or receives telemetry from cloud services and transfers it to the SamurAI Platform.

How are collectors used?

The type of collector required depends on how the telemetry is sourced:

  • Local Collector is used when a locally deployed ingestion point is required to collect and forward telemetry
  • Cloud Collector is used when telemetry can be accessed directly from cloud services, APIs, or cloud storage

In many cases, the appropriate collector is determined automatically as part of the integration configuration.

How do SamurAI Collectors fit into the platform?

SamurAI Collectors are part of the telemetry ingestion layer within the SamurAI Platform.

  • Collectors receive telemetry from source systems
  • Data is securely transferred to the SamurAI Platform
  • Telemetry is ingested, normalized, and processed for detection and response

This architecture enables consistent telemetry collection across hybrid environments, regardless of where systems are hosted.

Next steps

  • Review the Supported Integrations and associated Integration Guides to determine the required collector type. Each Integration Guide includes details on whether a Local Collector or Cloud Collector is used, and this is also shown in the SamurAI Portal during integration setup.

  • You can also work directly in the SamurAI Portal to explore and configure integrations.

To continue and for additional information for each collector type:

1 - Local Collector

What is the Local Collector?

The SamurAI Local Collector is a deployable component that enables the collection and secure transfer of telemetry data from client-controlled environments to the SamurAI Platform.

It is used when a local ingestion point is required to collect and forward telemetry from systems that are not directly integrated with the platform.

Multiple Local Collectors can be deployed by a client as necessary to support scaling, segmentation of data sources, or architectural requirements.

What does the Local Collector do?

The Local Collector performs the following functions:

  • Receives telemetry from systems within the client environment
  • Processes and forwards data to the SamurAI Platform
  • Supports multiple ingestion methods, such as syslog and log forwarding mechanisms
  • Securely transmits data to the SamurAI Platform
  • Buffers data locally during temporary connectivity interruptions

The Local Collector integrates with the broader SamurAI telemetry ingestion architecture, alongside cloud-based and API-driven collection methods.

How does the Local Collector work?

The Local Collector operates as an intermediary between source systems and the SamurAI Platform.

  • Telemetry is generated by systems within the client environment
  • Data is forwarded to the Local Collector
  • The Local Collector receives and prepares the data for ingestion
  • Data is securely transmitted to the SamurAI Platform
  • The platform processes and analyzes the telemetry

Depending on the integration type, the Local Collector supports both push and pull data collection models.

Where can the Local Collector be deployed?

The Local Collector can be deployed within environments, including:

  • On-premises virtual infrastructure (for example VMware vSphere or Microsoft Hyper‑V)
  • Cloud-hosted virtual machines (for example Amazon EC2 or Microsoft Azure)
  • NTT Smart Data Platform (SDPF)

This flexibility allows the Local Collector to be positioned close to telemetry sources while maintaining secure connectivity to the SamurAI Platform.

What data sources are supported?

The Local Collector can ingest telemetry from a range of systems, including:

  • Network infrastructure (for example firewalls and proxies)
  • Servers and operating systems
  • Identity and authentication systems
  • Security tools that generate log-based telemetry

Telemetry is typically forwarded using syslog or supported log forwarding methods.

What is the data flow?

The Local Collector participates in the SamurAI ingestion pipeline as follows:

  • Receives telemetry from source systems
  • Forwards data securely to the SamurAI Platform
  • Data is ingested, normalized, and processed for detection and response

When should the Local Collector be used?

The Local Collector is typically used when:

  • Telemetry originates from internal or client-controlled environments
  • Systems cannot be integrated directly using API-based methods
  • A local ingestion point is required due to network or architectural constraints

Who is responsible for the Local Collector?

The client is responsible for the deployment, installation, and configuration of the Local Collector, including the underlying infrastructure (for example virtual machine, storage, networking, and cloud-hosted environments such as Amazon EC2 or Microsoft Azure).

The client is also responsible for configuring data sources to forward telemetry to the Local Collector and ensuring ongoing connectivity between the Local Collector and the SamurAI Platform.

The SamurAI team is responsible for providing and maintaining the Local Collector software and ensuring its integration with the SamurAI Platform.

The SamurAI platform monitors the health and availability of the Local Collector and will notify registered users if any issues are detected. Once issues are resolved, a notification will confirm the return to a healthy state.

If the SamurAI team identifies that a Local Collector is undersized or under heavy load, we will liaise with the client to determine the appropriate next steps, which may include adjustments to allocated resources or deployment architecture.

What’s Next?

Review the requirements to determine what is needed before deployment and configuration of a Local Collector.

1.1 - Requirements

What you need to get started

  • Access to the SamurAI Portal and your specific tenant.
  • A supported deployment platform for the Local Collector. Supported hypervisors and cloud platforms are listed below.
  • A virtual machine that meets the minimum virtual machine requirements.
  • The required network changes to meet the Collector connectivity requirements.
  • A static IP address for the Collector and DNS server IP addresses, unless you use DHCP.
  • Access to the products where you need to make the changes described in the relevant integration guide.

Supported hypervisors

HypervisorSupported version or requirement
VMware ESXiESXi 8.x and ESXi 9.x
Microsoft Hyper-VHyper-V 2016 and later; deploy the Local Collector as a Generation 2 virtual machine.
Proxmox Virtual EnvironmentProxmox VE 8.4.1 and later.
KVM-based environmentsKVM environments that support UEFI virtual machines and can import the Local Collector KVM bundle.

Supported cloud platforms

PlatformSupported instance types or requirements
Amazon EC2Nitro-based instances using HVM virtualization, Ubuntu Server 22.04 LTS
Azure Virtual MachineUbuntu Server 22.04 virtual machine that meet the minimum requirements.
NTT Smart Data Platform (SDPF)Ubuntu Server instances that meet the minimum requirements.

Minimum virtual machine requirements

ResourceRequirement
CPU2 vCPU
Memory4 GB RAM

Connectivity required for the Collector

The Collector requires connectivity to the resources listed below. Update security controls, such as firewall rules, proxy settings, and DNS configuration, as needed to allow the required communications.

FunctionProtocolPortSourceDestinationDetails
Enrolment, TelemetryTCP443Collector*.*.security.ntt

nttsecurity.io
.nttsecurity.io
.*.nttsecurity.io

samurai-xdr-prod-westeurope-xgliuoit.azure-api.net
All regular backend communication, telemetry
Remote ManagementTCP443Collectorra.cto.nttsecurity.io

deb.releases.teleport.dev

apt.releases.teleport.dev
Used for remote administration of Collector (this is not mandatory and used when troubleshooting)
NTPUDP123CollectorClient infrastructure (NTP server(s)) if configured in SamurAI Portal

OR

0.ubuntu.pool.ntp.org

1.ubuntu.pool.ntp.org

2.ubuntu.pool.ntp.org

3.ubuntu.pool.ntp.org
Time synchronization
DNSUDP53CollectorClient infrastructure (DNS server(s)) or external DNS servers (based on your Collector configuration)Domain name resolution
Ubuntu updatesTCP80, 443Collector*.ubuntu.com

api.snapcraft.io
Ubuntu software repository
Container ManagementTCP443Collectordocker.com

*.docker.com (private container registry)

docker.io (private container registry)

*.docker.io (private container registry)
Private container registry
Amazon Cloud dependenciesTCP443Collector*.cloudfront.netAmazon CDN used by Collector API
Log storageTCP443Collector*.s3.*.amazonaws.comAmazon Cloud storage (this is not mandatory and used when troubleshooting)
Telemetry data(based on product - see Integration guide)Client ProductCollectorFrequent data transfer (based on product)

What’s next?

You now understand the supported deployment platforms, minimum virtual machine requirements, and required connectivity. Proceed to Deployment.

1.2 - Deployment

The need for a Local Collector depends on the product being integrated with the SamurAI platform. This is indicated in the relevant Product Integration Guide.

Create, configure and download a Collector

  1. Log in to the SamurAI Portal, select Telemetry, and then select Collectors from the main menu.
  2. Select Create Collector.
  3. Select Local Collector.
  4. Complete the fields as required.
FieldDescription
Collector nameA nickname for the Collector.
Description (Optional)A description of the Collector, such as the property name where it is installed.
Location (Optional)Useful when you have Collectors in multiple locations.
HostnameA hostname for the Collector.
Proxy Server IP (Optional)An optional HTTP proxy URL containing a hostname or IP address and port, for example https://192.168.1.254:8080.
NTP Servers (Optional)Your NTP server IP addresses.
DHCP or StaticSelect DHCP, or specify a static IP address and network information.
  1. Select Create Collector.
  2. Select the Collector by clicking the name provided in step 4.
  3. Select Download.

The files you download depend on the deployment platform.

  • Configuration

    • ISO — Collector-specific configuration file.
    • Required for all virtual-machine deployments. Mount this ISO when the Collector starts for the first time so that it can configure and register with the SamurAI platform.
  • Cloud init

    • AWS — Cloud-init data for an AWS instance.
    • Azure — Cloud-init data for an Azure virtual machine.
    • SDPF — Cloud-init data for an NTT Smart Data Platform (SDPF) instance.
  • Virtual machine

    • OVA — Virtual appliance package for VMware vSphere and Proxmox VE.
      • Includes the virtual disk image and virtual-machine configuration.
    • VMDK — Virtual disk image for VMware vSphere.
      • For manual deployment; it requires manual virtual-machine configuration.
    • VHDX — Virtual hard-disk image for Microsoft Hyper-V.
    • KVM bundle — Virtual-machine package for KVM-based environments.
      • The bundle contains the files required to deploy the Local Collector on a KVM platform.
  1. Download the Collector configuration ISO file and the file required for your selected deployment platform.

Install a Collector

Select the section relevant to your deployment platform:

VMware vSphere

Follow the VMware documentation:

  1. When prompted for a virtual-machine name, use a meaningful name, for example samurai-nttsh-collector.
  2. Select the Local Collector OVA file downloaded from the SamurAI Portal.
  3. Ensure the virtual machine is configured to use UEFI firmware.
  4. Configure CPU, memory, storage, and networking in accordance with the Minimum Virtual Machine Requirements.

After deployment, configure the virtual machine to use the Local Collector configuration ISO file. Refer to VMware documentation:

  1. Select the Collector configuration ISO file downloaded from the SamurAI Portal when prompted to select an ISO file.
  2. Ensure that the CD/DVD drive is connected when the virtual machine starts.
  3. Power on the virtual machine.

Microsoft Hyper-V

Follow Microsoft documentation:

  1. When prompted for a virtual-machine name, use a meaningful name, for example samurai-nttsh-collector.
  2. Configure the virtual machine to use UEFI firmware.
  3. Configure memory and networking in accordance with the Minimum Virtual Machine Requirements.
  4. When prompted to connect a virtual hard disk, select the VHDX file downloaded from the SamurAI Portal.
  5. Attach the Collector configuration ISO file to the virtual DVD drive and ensure that the drive is connected at startup.
  6. Start the virtual machine.

Proxmox Virtual Environment

Follow the Proxmox documentation:

  1. Create or select storage to use as the import source.
  2. Use the OVA/OVF import workflow to import the Local Collector OVA file downloaded from the SamurAI Portal.
  3. Ensure that the imported virtual machine is configured to use UEFI firmware.
  4. Configure CPU, memory, storage, and networking in accordance with the Minimum Virtual Machine Requirements.

Import the Local Collector configuration ISO file to Proxmox:

  1. Navigate to Datacenter and select Storage.
  2. Select the storage location where you want to store the ISO file.
  3. Select ISO Images.

Proxmox: select ISO Images

  1. Select Upload.
  2. Select the Local Collector configuration ISO file and upload it using the default settings.

Proxmox: upload the configuration ISO

Configure the Local Collector virtual machine to use the configuration ISO file:

  1. Select the Local Collector virtual machine, select Hardware, and then select Add.

Proxmox: open VM hardware settings

  1. Select CD/DVD Drive.

Proxmox: add CD/DVD drive

  1. Select Use CD/DVD disk image file (ISO), locate the Local Collector configuration ISO file, and then select Add.

Proxmox: select the configuration ISO

  1. Confirm that the network interface is available as Network Device (net0).
  2. Start the virtual machine.

KVM-based environments

This section applies to KVM environments, including platforms that use libvirt, QEMU/KVM, or another KVM management interface. Because KVM implementations and management interfaces differ, follow the documentation provided by your KVM platform for the virtual-machine creation and import workflow.

Prerequisites:

  1. Download the Collector configuration ISO file for the Collector you created.
  2. Download the Local Collector KVM bundle from the SamurAI Portal.
  3. Extract the KVM bundle.

Use your KVM platform documentation to create or import a virtual machine using the extracted Local Collector image.

When creating or configuring the Local Collector virtual machine:

  1. Configure the virtual machine to use UEFI firmware.
  2. Configure CPU, memory, storage, and networking in accordance with the Minimum Virtual Machine Requirements.
  3. Attach the Local Collector configuration ISO file as a virtual CD/DVD drive.
  4. Ensure the virtual CD/DVD drive is connected when the virtual machine starts for the first time.
  5. Start the virtual machine.

For guidance on KVM virtual-machine configuration, refer to the documentation for your management platform. Examples include:

Amazon EC2

Prerequisite steps:

  1. Download the AWS cloud-init.yaml file from Create, configure and download a Collector. You will use this file during EC2 instance deployment.

Follow Amazon documentation to launch an EC2 instance:

Apply the following adjustments while following the Amazon documentation:

  1. Select Ubuntu Server 22.04 LTS AMI.
  2. Select the latest supported Ubuntu AMI.
  3. Select an instance type that meets the Minimum Virtual Machine Requirements.
  4. Configure the key pair and network settings according to your organisation’s policies. Ensure network settings fulfil the Connectivity required for the Collector.
  5. In Configure storage:
  1. In Advanced details, paste the contents of the AWS cloud-init.yaml file into User data. Do not select User data has already been base64 encoded.
  2. Complete the remaining instance configuration according to your organisation’s requirements and the Amazon documentation.

Azure Virtual Machine

Prerequisite steps:

  1. Download the Azure cloud-init.yaml file from Create, configure and download a Collector. You will use this file during Azure virtual-machine deployment.

Follow Microsoft documentation to create an Azure virtual machine:

Apply the following adjustments while following the Microsoft documentation:

  1. Under the Basics tab, select Ubuntu Server 22.04 LTS as the image.
  2. Under the Basics tab, select a suitable size that meets the Minimum Virtual Machine Requirements.
  3. Under the Disks tab, add one data disk of at least 500 GiB, sized in accordance with the Minimum Virtual Machine Requirements.
  1. Under the Advanced tab, paste the contents of cloud-init.yaml into the Custom data field.

NTT Smart Data Platform (SDPF)

Prerequisite steps:

  1. Download the SDPF cloud-init.yaml file from Create, configure and download a Collector. You will use this file during instance creation.

Follow NTT documentation to create a server instance:

Apply the following adjustments while following the NTT documentation:

  1. When selecting the image, select the latest Ubuntu 24.04 official image.
  2. When selecting compute series and size, select a suitable specification that meets the Minimum Virtual Machine Requirements.
  3. Add a separate data disk of at least 500 GB, sized in accordance with the Minimum Virtual Machine Requirements.
  1. When selecting the logical network, ensure that it fulfils the Connectivity required for the Collector. This typically requires an Internet Gateway, logical network, subnet, and potentially firewall rules that allow the Collector’s required outbound connectivity.
  2. In the Post-install script field, select Direct Input and paste the contents of the cloud-init.yaml file.

Deleting a Collector

To delete a Local Collector:

  1. In the SamurAI Portal, select Telemetry and then Collectors.
  2. Select the relevant Collector.
  3. On the right side of the relevant Collector, select More Options () and then select Delete Collector.
  4. Review the warning. To confirm the destructive action, enter DELETE and select Delete Collector.

Replacing a Collector

If a Local Collector virtual machine is lost because of corruption or damage, such as a major storage failure, delete the existing Collector in the SamurAI Portal, discard the old virtual-machine image, and create a new Collector by following the installation process.

What’s next?

You have now deployed and configured your Local Collector.

Refer to Local Collector Details for information about validating Collector status and additional configuration.

1.3 - Local Collector Details

Validate Collector Status

  1. Click Telemetry and select Collectors from the main menu

  2. Select the relevant Collector from the presented list

  3. View Status

IndicatorStatusDescription
PendingCollector components installing / provisioning or awaiting status
UnknownThe SamurAI platform is unable to determine a status
OKHealthy
WarningWarning status will be displayed if the Collector is experiencing any issues e.g components are experiencing problems
CriticalCritical status will be displayed and an email notification will be sent to registered users (by default) if the SamurAI platform cannot communicate with the Collector

After you provision a Collector VM and start it, it will go through a process of installing updates and modules specified in the configuration ISO file which you downloaded. The time taken for this process is dependent on factors like the speed of the hardware you are running the Collector on and connectivity to the repositories that it downloads updates from. In some cases this process can take around 30 minutes.

If you have any problems, please submit a ticket via the SamurAI Portal.

Collector Email Notifications

By default email notifications are enabled. The SamurAI platform sends email notifications to registered users when a Collector is reported as Critical (e.g. the SamurAI platform cannot communicate to the Collector) however this is customizable by users for any Collector status.

Enable or Disable Email Notifications

  1. Click on More Options () to the right of the table
  2. Select Notifications
  3. Toggle the setting to enable or disable by selecting the bell icon. Alternatively you can select the default setting
  4. Click Save

You can also achieve this per individual Collector by:

  1. Click on More Options () to the left of the Collector
  2. Select Notifications
  3. Toggle the setting to enable or disable by selecting the bell icon. Alternatively you can select the default setting (send notification).
  4. Click Save

What’s next?

The next step is to start configuring integrations which will allow the SamurAI platform to start receiving your telemetry data.

Select Integrations Overview for more information on integrations and where to start.

If you require high availability for your collector, this can be achieved using the capabilities of your virtualization platform.

2 - Cloud Collector

What is a Cloud Collector?

The SamurAI Cloud Collector enables the collection and secure transfer of telemetry data from cloud-based services and platforms to the SamurAI Platform.

It is used when telemetry can be accessed directly from the source without requiring a locally deployed component.

The Cloud Collector is a platform-managed component that integrates with supported services to retrieve or receive telemetry data.

Multiple Cloud Collectors may be used as part of a deployment, depending on the integration design and architecture.

What does the Cloud Collector do?

The Cloud Collector performs the following functions:

  • Retrieves or receives telemetry from cloud-based services and platforms
  • Supports multiple integration methods depending on the data source
  • Securely transfers telemetry to the SamurAI Platform
  • Enables ingestion of telemetry without requiring client-managed infrastructure

The Cloud Collector operates as part of the SamurAI telemetry ingestion architecture, alongside Local Collectors.

How does the Cloud Collector work?

The Cloud Collector integrates directly with supported services to access telemetry data.

  • Telemetry is generated by cloud services or external platforms
  • The Cloud Collector receives or retrieves telemetry using the appropriate integration method
  • Data is securely transferred to the SamurAI Platform
  • The platform ingests, processes, and analyzes the telemetry

Depending on the integration type, the Cloud Collector supports both push and pull data collection models.

How is telemetry accessed?

The Cloud Collector supports multiple integration methods depending on the source system:

  • API-based collection – telemetry is retrieved directly from service APIs (for example SaaS or cloud security platforms)
  • Cloud storage ingestion – telemetry is read from cloud storage (for example AWS S3 or Azure Blob Storage)
  • Push-based ingestion – telemetry is sent directly to the platform over HTTP (for example Splunk HTTP Event Collector)

The method used is determined by the supported integration and data source.

Where is the Cloud Collector deployed?

The Cloud Collector is a platform-managed component. It does not require software to be deployed on client-managed infrastructure.

Where a cloud provider deployment is required for a supported integration, deployment-specific configuration and provisioning steps are described in the relevant Deployment guide.

It integrates directly with supported services to access telemetry data.

When should the Cloud Collector be used?

The Cloud Collector is typically used when:

  • Telemetry is available from cloud-based services or SaaS platforms
  • Data can be accessed directly via APIs, cloud storage, or push-based ingestion
  • No local ingestion point is required

Who is responsible for the Cloud Collector

The Cloud Collector is managed as part of the SamurAI Platform and does not require deployment or maintenance within the client environment.

The SamurAI team is responsible for the operation, health, and availability of the Cloud Collector.

The SamurAI platform monitors the status of the Cloud Collector and will notify registered users if any issues are detected. Once issues are resolved, a notification will confirm when a healthy state has been restored.

The client is responsible for configuring each integration and ensuring that required data sources remain accessible. This includes setting up and maintaining the required credentials, permissions, connection details, and cloud-provider configuration described in the relevant Integration and Deployment Guides.

The client is also responsible for reviewing Collector status and responding to configuration issues that prevent telemetry from being collected or accessed.

What’s next?

Review Deployment to understand how to create and deploy a Cloud Collector.

2.1 - Deployment

The need for a Cloud Collector is based on the specific product being integrated with the SamurAI platform. This will be clearly indicated within the Product Integration Guide.

Create a Cloud Collector

  1. From the SamurAI Portal, click Telemetry and select Collectors from the main menu

  2. Select Create Collector

  3. Select Cloud collector

  4. Complete the fields as required.

FieldDescription
Collector nameA name for the collector
Description (Optional)A description of your collector
ProviderSelect the correct Provider
  1. Select Create Collector

  2. Follow the relevant section below based on your provider:

Microsoft Azure

  1. Click Deploy to Azure and you will be redirected to the Microsoft Azure login.
  1. An Azure Resource Manager (ARM) template will be launched, follow the steps and complete the necessary fields within the template:

Project Details

FieldDescription
SubscriptionSelect your Azure subscription
Resource GroupCreate or select your Resource Group

Instance Details

FieldDescription
RegionSelect the Azure region to deploy the Collector into
Collector Name(this is auto populated from the SamurAI Portal Collector name you defined)
Collector Id(this is auto populated from SamurAI)
Passkey(this is auto populated from SamurAI)
Data Retention DaysThe amount of days to keep the data in the container (default is 7 days)
Storage Account NameThe name of the Storage Account (a default is auto populated)
Event Grid Topic NameThe name of the Event Grid Topic (a default is auto populated)
Deployment Script NameThe name of the Deployment Script used for auto registration (a default is auto populated)
EndpointSamuraAI Endpoint (Do not modify)
  1. Select Next

  2. Select Review and Create

  3. Upon creation your Collector status will be updated to Healthy.

  4. You can now refer to the relevant Product Integration Guides.

Amazon Web Services (AWS)

  1. Click Launch Stack and you will be redirected to the AWS login.
  1. Login to your AWS account with administrative permissions.

  2. The SamurAI cloud formation template will be displayed.

  3. If you have an existing S3 Bucket enter the name within the Parameters section under Enable SamurAI ingestion on existing S3 bucket. If you have no existing S3 bucket, leave this field blank and a new S3 bucket will be created.

  1. If you are integrating Cisco Umbrella, be sure to update Cisco Umbrella under the Parameters section to Yes.

  2. Click Create Stack.

  3. Upon creation of the stack your Collector status will be updated to Healthy.

  4. You can now refer to the relevant Product Integration Guides.

Additional required steps when using an existing bucket

  1. Add the following to the bucket policy, please update the json with the correct bucket name.
 {
    "Effect": "Allow",
    "Principal": {
        "AWS": "arn:aws:iam::600502389717:user/samurai-xdr-s3-reader-user"
    },
    "Action": [
        "s3:GetObject",
        "s3:ListBucket"
    ],
    "Resource": [
        "arn:aws:s3:::BUCKET_NAME",
        "arn:aws:s3:::BUCKET_NAME/*"
    ]
}
  1. Create an Event Notification in the bucket properties.

  2. Enter an Event Name for the notification, leave the Prefix and Suffix boxes blank.

  3. Select All object create events

  4. Under Destination, select SNS Topic and select the SNS topic that was created by the Cloud Formation Template from the drop down and click Save Changes.

Splunk HTTP Event Collector

  1. If you selected this option you will be presented with the following information:
  • API URL
  • Token

Copy these entries as you will need them when completing your integration.

  1. Select Close.

Deleting a Collector

If you need to delete a Cloud collector you can do so by following the steps below:

  1. From your SamurAI Portal click Telemetry and select Collectors from the main menu
  2. Select the relevant collector from your list
  3. On the right hand side of the relevant collector, click on More Options () and select Delete Collector
  4. The following warning will appear: ‘Warning: This is a destructive action and cannot be reversed.’. To ensure you intended to delete the collector you will need to type DELETE in the window and select Delete Collector

What’s next?

You should now have a Cloud Collector running.

Refer to Cloud Collector Details for information on validating Collector Status and details.

2.2 - Cloud Collector Details

Validate Collector Status

  1. Select Telemetry and Collectors from the main menu

  2. Select the relevant Collector from the presented list

  3. View Status

IndicatorStatusDescription
PendingCollector components installing / provisioning or awaiting status
UnknownThe SamurAI platform is unable to determine a status
OKHealthy
WarningWarning status will be displayed if the Collector is experiencing any issues e.g components are experiencing problems
CriticalCritical status will be displayed and an email notification will be sent to registered users (by default) if the SamurAI platform cannot communicate with the Collector

Collector Email Notifications

By default email notifications are enabled. The SamurAI platform sends email notifications to registered users when a Collector is reported as Critical (e.g. the SamurAI platform cannot communicate to the Collector) however this is customizable by users for any Collector status.

Enable or Disable Email Notifications

  1. Click on More Options () to the right of the table
  2. Select Notifications
  3. Toggle the setting to enable or disable by selecting the bell icon. Alternatively you can select the default setting
  4. Click Save

You can also achieve this per individual Collector by:

  1. Click on More Options () to the left of the Collector
  2. Select Notifications
  3. Toggle the setting to enable or disable by selecting the bell icon. Alternatively you can select the default setting (send notification).
  4. Click Save

What’s next?

The next step is to start configuring integrations which will allow the SamurAI platform to collect your telemetry data.

Select Integrations Overview for more information on integrations and where to start.