This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

Cloud Collector

What is a Cloud Collector?

The SamurAI Cloud Collector enables the collection and secure transfer of telemetry data from cloud-based services and platforms to the SamurAI Platform.

It is used when telemetry can be accessed directly from the source without requiring a locally deployed component.

The Cloud Collector is a platform-managed component that integrates with supported services to retrieve or receive telemetry data.

Multiple Cloud Collectors may be used as part of a deployment, depending on the integration design and architecture.

What does the Cloud Collector do?

The Cloud Collector performs the following functions:

  • Retrieves or receives telemetry from cloud-based services and platforms
  • Supports multiple integration methods depending on the data source
  • Securely transfers telemetry to the SamurAI Platform
  • Enables ingestion of telemetry without requiring client-managed infrastructure

The Cloud Collector operates as part of the SamurAI telemetry ingestion architecture, alongside Local Collectors.

How does the Cloud Collector work?

The Cloud Collector integrates directly with supported services to access telemetry data.

  • Telemetry is generated by cloud services or external platforms
  • The Cloud Collector receives or retrieves telemetry using the appropriate integration method
  • Data is securely transferred to the SamurAI Platform
  • The platform ingests, processes, and analyzes the telemetry

Depending on the integration type, the Cloud Collector supports both push and pull data collection models.

How is telemetry accessed?

The Cloud Collector supports multiple integration methods depending on the source system:

  • API-based collection – telemetry is retrieved directly from service APIs (for example SaaS or cloud security platforms)
  • Cloud storage ingestion – telemetry is read from cloud storage (for example AWS S3 or Azure Blob Storage)
  • Push-based ingestion – telemetry is sent directly to the platform over HTTP (for example Splunk HTTP Event Collector)

The method used is determined by the supported integration and data source.

Where is the Cloud Collector deployed?

The Cloud Collector is a platform-managed component. It does not require software to be deployed on client-managed infrastructure.

Where a cloud provider deployment is required for a supported integration, deployment-specific configuration and provisioning steps are described in the relevant Deployment guide.

It integrates directly with supported services to access telemetry data.

When should the Cloud Collector be used?

The Cloud Collector is typically used when:

  • Telemetry is available from cloud-based services or SaaS platforms
  • Data can be accessed directly via APIs, cloud storage, or push-based ingestion
  • No local ingestion point is required

Who is responsible for the Cloud Collector

The Cloud Collector is managed as part of the SamurAI Platform and does not require deployment or maintenance within the client environment.

The SamurAI team is responsible for the operation, health, and availability of the Cloud Collector.

The SamurAI platform monitors the status of the Cloud Collector and will notify registered users if any issues are detected. Once issues are resolved, a notification will confirm when a healthy state has been restored.

The client is responsible for configuring each integration and ensuring that required data sources remain accessible. This includes setting up and maintaining the required credentials, permissions, connection details, and cloud-provider configuration described in the relevant Integration and Deployment Guides.

The client is also responsible for reviewing Collector status and responding to configuration issues that prevent telemetry from being collected or accessed.

What’s next?

Review Deployment to understand how to create and deploy a Cloud Collector.

1 - Deployment

The need for a Cloud Collector is based on the specific product being integrated with the SamurAI platform. This will be clearly indicated within the Product Integration Guide.

Create a Cloud Collector

  1. From the SamurAI Portal, click Telemetry and select Collectors from the main menu

  2. Select Create Collector

  3. Select Cloud collector

  4. Complete the fields as required.

FieldDescription
Collector nameA name for the collector
Description (Optional)A description of your collector
ProviderSelect the correct Provider
  1. Select Create Collector

  2. Follow the relevant section below based on your provider:

Microsoft Azure

  1. Click Deploy to Azure and you will be redirected to the Microsoft Azure login.
  1. An Azure Resource Manager (ARM) template will be launched, follow the steps and complete the necessary fields within the template:

Project Details

FieldDescription
SubscriptionSelect your Azure subscription
Resource GroupCreate or select your Resource Group

Instance Details

FieldDescription
RegionSelect the Azure region to deploy the Collector into
Collector Name(this is auto populated from the SamurAI Portal Collector name you defined)
Collector Id(this is auto populated from SamurAI)
Passkey(this is auto populated from SamurAI)
Data Retention DaysThe amount of days to keep the data in the container (default is 7 days)
Storage Account NameThe name of the Storage Account (a default is auto populated)
Event Grid Topic NameThe name of the Event Grid Topic (a default is auto populated)
Deployment Script NameThe name of the Deployment Script used for auto registration (a default is auto populated)
EndpointSamuraAI Endpoint (Do not modify)
  1. Select Next

  2. Select Review and Create

  3. Upon creation your Collector status will be updated to Healthy.

  4. You can now refer to the relevant Product Integration Guides.

Amazon Web Services (AWS)

  1. Click Launch Stack and you will be redirected to the AWS login.
  1. Login to your AWS account with administrative permissions.

  2. The SamurAI cloud formation template will be displayed.

  3. If you have an existing S3 Bucket enter the name within the Parameters section under Enable SamurAI ingestion on existing S3 bucket. If you have no existing S3 bucket, leave this field blank and a new S3 bucket will be created.

  1. If you are integrating Cisco Umbrella, be sure to update Cisco Umbrella under the Parameters section to Yes.

  2. Click Create Stack.

  3. Upon creation of the stack your Collector status will be updated to Healthy.

  4. You can now refer to the relevant Product Integration Guides.

Additional required steps when using an existing bucket

  1. Add the following to the bucket policy, please update the json with the correct bucket name.
 {
    "Effect": "Allow",
    "Principal": {
        "AWS": "arn:aws:iam::600502389717:user/samurai-xdr-s3-reader-user"
    },
    "Action": [
        "s3:GetObject",
        "s3:ListBucket"
    ],
    "Resource": [
        "arn:aws:s3:::BUCKET_NAME",
        "arn:aws:s3:::BUCKET_NAME/*"
    ]
}
  1. Create an Event Notification in the bucket properties.

  2. Enter an Event Name for the notification, leave the Prefix and Suffix boxes blank.

  3. Select All object create events

  4. Under Destination, select SNS Topic and select the SNS topic that was created by the Cloud Formation Template from the drop down and click Save Changes.

Splunk HTTP Event Collector

  1. If you selected this option you will be presented with the following information:
  • API URL
  • Token

Copy these entries as you will need them when completing your integration.

  1. Select Close.

Deleting a Collector

If you need to delete a Cloud collector you can do so by following the steps below:

  1. From your SamurAI Portal click Telemetry and select Collectors from the main menu
  2. Select the relevant collector from your list
  3. On the right hand side of the relevant collector, click on More Options () and select Delete Collector
  4. The following warning will appear: ‘Warning: This is a destructive action and cannot be reversed.’. To ensure you intended to delete the collector you will need to type DELETE in the window and select Delete Collector

What’s next?

You should now have a Cloud Collector running.

Refer to Cloud Collector Details for information on validating Collector Status and details.

2 - Cloud Collector Details

Validate Collector Status

  1. Select Telemetry and Collectors from the main menu

  2. Select the relevant Collector from the presented list

  3. View Status

IndicatorStatusDescription
PendingCollector components installing / provisioning or awaiting status
UnknownThe SamurAI platform is unable to determine a status
OKHealthy
WarningWarning status will be displayed if the Collector is experiencing any issues e.g components are experiencing problems
CriticalCritical status will be displayed and an email notification will be sent to registered users (by default) if the SamurAI platform cannot communicate with the Collector

Collector Email Notifications

By default email notifications are enabled. The SamurAI platform sends email notifications to registered users when a Collector is reported as Critical (e.g. the SamurAI platform cannot communicate to the Collector) however this is customizable by users for any Collector status.

Enable or Disable Email Notifications

  1. Click on More Options () to the right of the table
  2. Select Notifications
  3. Toggle the setting to enable or disable by selecting the bell icon. Alternatively you can select the default setting
  4. Click Save

You can also achieve this per individual Collector by:

  1. Click on More Options () to the left of the Collector
  2. Select Notifications
  3. Toggle the setting to enable or disable by selecting the bell icon. Alternatively you can select the default setting (send notification).
  4. Click Save

What’s next?

The next step is to start configuring integrations which will allow the SamurAI platform to collect your telemetry data.

Select Integrations Overview for more information on integrations and where to start.