Local Collector

What is the Local Collector?

The SamurAI Local Collector is a deployable component that enables the collection and secure transfer of telemetry data from client-controlled environments to the SamurAI Platform.

It is used when a local ingestion point is required to collect and forward telemetry from systems that are not directly integrated with the platform.

Multiple Local Collectors can be deployed by a client as necessary to support scaling, segmentation of data sources, or architectural requirements.

What does the Local Collector do?

The Local Collector performs the following functions:

  • Receives telemetry from systems within the client environment
  • Processes and forwards data to the SamurAI Platform
  • Supports multiple ingestion methods, such as syslog and log forwarding mechanisms
  • Securely transmits data to the SamurAI Platform
  • Buffers data locally during temporary connectivity interruptions

The Local Collector integrates with the broader SamurAI telemetry ingestion architecture, alongside cloud-based and API-driven collection methods.

How does the Local Collector work?

The Local Collector operates as an intermediary between source systems and the SamurAI Platform.

  • Telemetry is generated by systems within the client environment
  • Data is forwarded to the Local Collector
  • The Local Collector receives and prepares the data for ingestion
  • Data is securely transmitted to the SamurAI Platform
  • The platform processes and analyzes the telemetry

Depending on the integration type, the Local Collector supports both push and pull data collection models.

Where can the Local Collector be deployed?

The Local Collector can be deployed within environments, including:

  • On-premises virtual infrastructure (for example VMware vSphere or Microsoft Hyper‑V)
  • Cloud-hosted virtual machines (for example Amazon EC2 or Microsoft Azure)
  • NTT Smart Data Platform (SDPF)

This flexibility allows the Local Collector to be positioned close to telemetry sources while maintaining secure connectivity to the SamurAI Platform.

What data sources are supported?

The Local Collector can ingest telemetry from a range of systems, including:

  • Network infrastructure (for example firewalls and proxies)
  • Servers and operating systems
  • Identity and authentication systems
  • Security tools that generate log-based telemetry

Telemetry is typically forwarded using syslog or supported log forwarding methods.

What is the data flow?

The Local Collector participates in the SamurAI ingestion pipeline as follows:

  • Receives telemetry from source systems
  • Forwards data securely to the SamurAI Platform
  • Data is ingested, normalized, and processed for detection and response

When should the Local Collector be used?

The Local Collector is typically used when:

  • Telemetry originates from internal or client-controlled environments
  • Systems cannot be integrated directly using API-based methods
  • A local ingestion point is required due to network or architectural constraints

Who is responsible for the Local Collector?

The client is responsible for the deployment, installation, and configuration of the Local Collector, including the underlying infrastructure (for example virtual machine, storage, networking, and cloud-hosted environments such as Amazon EC2 or Microsoft Azure).

The client is also responsible for configuring data sources to forward telemetry to the Local Collector and ensuring ongoing connectivity between the Local Collector and the SamurAI Platform.

The SamurAI team is responsible for providing and maintaining the Local Collector software and ensuring its integration with the SamurAI Platform.

The SamurAI platform monitors the health and availability of the Local Collector and will notify registered users if any issues are detected. Once issues are resolved, a notification will confirm the return to a healthy state.

If the SamurAI team identifies that a Local Collector is undersized or under heavy load, we will liaise with the client to determine the appropriate next steps, which may include adjustments to allocated resources or deployment architecture.

What’s Next?

Review the requirements to determine what is needed before deployment and configuration of a Local Collector.