This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

Local Collector

What is the Local Collector?

The SamurAI Local Collector is a deployable component that enables the collection and secure transfer of telemetry data from client-controlled environments to the SamurAI Platform.

It is used when a local ingestion point is required to collect and forward telemetry from systems that are not directly integrated with the platform.

Multiple Local Collectors can be deployed by a client as necessary to support scaling, segmentation of data sources, or architectural requirements.

What does the Local Collector do?

The Local Collector performs the following functions:

  • Receives telemetry from systems within the client environment
  • Processes and forwards data to the SamurAI Platform
  • Supports multiple ingestion methods, such as syslog and log forwarding mechanisms
  • Securely transmits data to the SamurAI Platform
  • Buffers data locally during temporary connectivity interruptions

The Local Collector integrates with the broader SamurAI telemetry ingestion architecture, alongside cloud-based and API-driven collection methods.

How does the Local Collector work?

The Local Collector operates as an intermediary between source systems and the SamurAI Platform.

  • Telemetry is generated by systems within the client environment
  • Data is forwarded to the Local Collector
  • The Local Collector receives and prepares the data for ingestion
  • Data is securely transmitted to the SamurAI Platform
  • The platform processes and analyzes the telemetry

Depending on the integration type, the Local Collector supports both push and pull data collection models.

Where can the Local Collector be deployed?

The Local Collector can be deployed within environments, including:

  • On-premises virtual infrastructure (for example VMware vSphere or Microsoft Hyper‑V)
  • Cloud-hosted virtual machines (for example Amazon EC2 or Microsoft Azure)
  • NTT Smart Data Platform (SDPF)

This flexibility allows the Local Collector to be positioned close to telemetry sources while maintaining secure connectivity to the SamurAI Platform.

What data sources are supported?

The Local Collector can ingest telemetry from a range of systems, including:

  • Network infrastructure (for example firewalls and proxies)
  • Servers and operating systems
  • Identity and authentication systems
  • Security tools that generate log-based telemetry

Telemetry is typically forwarded using syslog or supported log forwarding methods.

What is the data flow?

The Local Collector participates in the SamurAI ingestion pipeline as follows:

  • Receives telemetry from source systems
  • Forwards data securely to the SamurAI Platform
  • Data is ingested, normalized, and processed for detection and response

When should the Local Collector be used?

The Local Collector is typically used when:

  • Telemetry originates from internal or client-controlled environments
  • Systems cannot be integrated directly using API-based methods
  • A local ingestion point is required due to network or architectural constraints

Who is responsible for the Local Collector?

The client is responsible for the deployment, installation, and configuration of the Local Collector, including the underlying infrastructure (for example virtual machine, storage, networking, and cloud-hosted environments such as Amazon EC2 or Microsoft Azure).

The client is also responsible for configuring data sources to forward telemetry to the Local Collector and ensuring ongoing connectivity between the Local Collector and the SamurAI Platform.

The SamurAI team is responsible for providing and maintaining the Local Collector software and ensuring its integration with the SamurAI Platform.

The SamurAI platform monitors the health and availability of the Local Collector and will notify registered users if any issues are detected. Once issues are resolved, a notification will confirm the return to a healthy state.

If the SamurAI team identifies that a Local Collector is undersized or under heavy load, we will liaise with the client to determine the appropriate next steps, which may include adjustments to allocated resources or deployment architecture.

What’s Next?

Review the requirements to determine what is needed before deployment and configuration of a Local Collector.

1 - Requirements

What you need to get started

  • Access to the SamurAI Portal and your specific tenant.
  • A supported deployment platform for the Local Collector. Supported hypervisors and cloud platforms are listed below.
  • A virtual machine that meets the minimum virtual machine requirements.
  • The required network changes to meet the Collector connectivity requirements.
  • A static IP address for the Collector and DNS server IP addresses, unless you use DHCP.
  • Access to the products where you need to make the changes described in the relevant integration guide.

Supported hypervisors

HypervisorSupported version or requirement
VMware ESXiESXi 8.x and ESXi 9.x
Microsoft Hyper-VHyper-V 2016 and later; deploy the Local Collector as a Generation 2 virtual machine.
Proxmox Virtual EnvironmentProxmox VE 8.4.1 and later.
KVM-based environmentsKVM environments that support UEFI virtual machines and can import the Local Collector KVM bundle.

Supported cloud platforms

PlatformSupported instance types or requirements
Amazon EC2Nitro-based instances using HVM virtualization.
Azure Virtual MachineUbuntu Server virtual machines that meet the minimum requirements.
NTT Smart Data Platform (SDPF)Ubuntu Server instances that meet the minimum requirements.

Minimum virtual machine requirements

ResourceRequirement
CPU2 vCPU
Disk500 GB dedicated data disk for spooling, in addition to the operating-system disk.
Memory4 GB RAM

Connectivity required for the Collector

The Collector requires connectivity to the resources listed below. Update security controls, such as firewall rules, proxy settings, and DNS configuration, as needed to allow the required communications.

FunctionProtocolPortSourceDestinationDetails
Enrolment, TelemetryTCP443Collector*.*.security.ntt

nttsecurity.io
.nttsecurity.io
.*.nttsecurity.io

samurai-xdr-prod-westeurope-xgliuoit.azure-api.net
All regular backend communication, telemetry
Remote ManagementTCP443Collectorra.cto.nttsecurity.io

deb.releases.teleport.dev

apt.releases.teleport.dev
Used for remote administration of Collector (this is not mandatory and used when troubleshooting)
NTPUDP123CollectorClient infrastructure (NTP server(s)) if configured in SamurAI Portal

OR

0.ubuntu.pool.ntp.org

1.ubuntu.pool.ntp.org

2.ubuntu.pool.ntp.org

3.ubuntu.pool.ntp.org
Time synchronization
DNSUDP53CollectorClient infrastructure (DNS server(s)) or external DNS servers (based on your Collector configuration)Domain name resolution
Ubuntu updatesTCP80, 443Collector*.ubuntu.com

api.snapcraft.io
Ubuntu software repository
Container ManagementTCP443Collectordocker.com

*.docker.com (private container registry)

docker.io (private container registry)

*.docker.io (private container registry)
Private container registry
Amazon Cloud dependenciesTCP443Collector*.cloudfront.netAmazon CDN used by Collector API
Log storageTCP443Collector*.s3.*.amazonaws.comAmazon Cloud storage (this is not mandatory and used when troubleshooting)
Telemetry data(based on product - see Integration guide)Client ProductCollectorFrequent data transfer (based on product)

What’s next?

You now understand the supported deployment platforms, minimum virtual machine requirements, and required connectivity. Proceed to Deployment.

2 - Deployment

The need for a Local Collector depends on the product being integrated with the SamurAI platform. This is indicated in the relevant Product Integration Guide.

Create, configure and download a Collector

  1. Log in to the SamurAI Portal, select Telemetry, and then select Collectors from the main menu.
  2. Select Create Collector.
  3. Select Local Collector.
  4. Complete the fields as required.
FieldDescription
Collector nameA nickname for the Collector.
Description (Optional)A description of the Collector, such as the property name where it is installed.
Location (Optional)Useful when you have Collectors in multiple locations.
HostnameA hostname for the Collector.
Proxy Server IP (Optional)An optional HTTP proxy URL containing a hostname or IP address and port, for example https://192.168.1.254:8080.
NTP Servers (Optional)Your NTP server IP addresses.
DHCP or StaticSelect DHCP, or specify a static IP address and network information.
  1. Select Create Collector.
  2. Select the Collector by clicking the name provided in step 4.
  3. Select Download.

The files you download depend on the deployment platform.

  • Configuration

    • ISO — Collector-specific configuration file.
    • Required for all virtual-machine deployments. Mount this ISO when the Collector starts for the first time so that it can configure and register with the SamurAI platform.
  • Cloud init

    • AWS — Cloud-init data for an AWS instance.
    • Azure — Cloud-init data for an Azure virtual machine.
    • SDPF — Cloud-init data for an NTT Smart Data Platform (SDPF) instance.
  • Virtual machine

    • OVA — Virtual appliance package for VMware vSphere and Proxmox VE.
      • Includes the virtual disk image and virtual-machine configuration.
    • VMDK — Virtual disk image for VMware vSphere.
      • For manual deployment; it requires manual virtual-machine configuration.
    • VHDX — Virtual hard-disk image for Microsoft Hyper-V.
    • KVM bundle — Virtual-machine package for KVM-based environments.
      • The bundle contains the files required to deploy the Local Collector on a KVM platform.
  1. Download the Collector configuration ISO file and the file required for your selected deployment platform.

Install a Collector

Select the section relevant to your deployment platform:

VMware vSphere

Follow the VMware documentation:

  1. When prompted for a virtual-machine name, use a meaningful name, for example samurai-nttsh-collector.
  2. Select the Local Collector OVA file downloaded from the SamurAI Portal.
  3. Ensure the virtual machine is configured to use UEFI firmware.
  4. Configure CPU, memory, storage, and networking in accordance with the Minimum Virtual Machine Requirements.

After deployment, configure the virtual machine to use the Local Collector configuration ISO file. Refer to VMware documentation:

  1. Select the Collector configuration ISO file downloaded from the SamurAI Portal when prompted to select an ISO file.
  2. Ensure that the CD/DVD drive is connected when the virtual machine starts.
  3. Power on the virtual machine.

Microsoft Hyper-V

Follow Microsoft documentation:

  1. When prompted for a virtual-machine name, use a meaningful name, for example samurai-nttsh-collector.
  2. Configure the virtual machine to use UEFI firmware.
  3. Configure memory and networking in accordance with the Minimum Virtual Machine Requirements.
  4. When prompted to connect a virtual hard disk, select the VHDX file downloaded from the SamurAI Portal.
  5. Attach the Collector configuration ISO file to the virtual DVD drive and ensure that the drive is connected at startup.
  6. Start the virtual machine.

Proxmox Virtual Environment

Follow the Proxmox documentation:

  1. Create or select storage to use as the import source.
  2. Use the OVA/OVF import workflow to import the Local Collector OVA file downloaded from the SamurAI Portal.
  3. Ensure that the imported virtual machine is configured to use UEFI firmware.
  4. Configure CPU, memory, storage, and networking in accordance with the Minimum Virtual Machine Requirements.

Import the Local Collector configuration ISO file to Proxmox:

  1. Navigate to Datacenter and select Storage.
  2. Select the storage location where you want to store the ISO file.
  3. Select ISO Images.

Proxmox: select ISO Images

  1. Select Upload.
  2. Select the Local Collector configuration ISO file and upload it using the default settings.

Proxmox: upload the configuration ISO

Configure the Local Collector virtual machine to use the configuration ISO file:

  1. Select the Local Collector virtual machine, select Hardware, and then select Add.

Proxmox: open VM hardware settings

  1. Select CD/DVD Drive.

Proxmox: add CD/DVD drive

  1. Select Use CD/DVD disk image file (ISO), locate the Local Collector configuration ISO file, and then select Add.

Proxmox: select the configuration ISO

  1. Confirm that the network interface is available as Network Device (net0).
  2. Start the virtual machine.

KVM-based environments

This section applies to KVM environments, including platforms that use libvirt, QEMU/KVM, or another KVM management interface. Because KVM implementations and management interfaces differ, follow the documentation provided by your KVM platform for the virtual-machine creation and import workflow.

Prerequisites:

  1. Download the Collector configuration ISO file for the Collector you created.
  2. Download the Local Collector KVM bundle from the SamurAI Portal.
  3. Extract the KVM bundle.

Use your KVM platform documentation to create or import a virtual machine using the extracted Local Collector image.

When creating or configuring the Local Collector virtual machine:

  1. Configure the virtual machine to use UEFI firmware.
  2. Configure CPU, memory, storage, and networking in accordance with the Minimum Virtual Machine Requirements.
  3. Attach the Local Collector configuration ISO file as a virtual CD/DVD drive.
  4. Ensure the virtual CD/DVD drive is connected when the virtual machine starts for the first time.
  5. Start the virtual machine.

For guidance on KVM virtual-machine configuration, refer to the documentation for your management platform. Examples include:

Amazon EC2

Prerequisite steps:

  1. Download the AWS cloud-init.yaml file from Create, configure and download a Collector. You will use this file during EC2 instance deployment.

Follow Amazon documentation to launch an EC2 instance:

Apply the following adjustments while following the Amazon documentation:

  1. Select Ubuntu as the AMI.
  2. Select the latest supported Ubuntu AMI.
  3. Select an instance type that meets the Minimum Virtual Machine Requirements.
  4. Configure the key pair and network settings according to your organisation’s policies. Ensure network settings fulfil the Connectivity required for the Collector.
  5. In Configure storage:
  1. In Advanced details, paste the contents of the AWS cloud-init.yaml file into User data. Do not select User data has already been base64 encoded.
  2. Complete the remaining instance configuration according to your organisation’s requirements and the Amazon documentation.

Azure Virtual Machine

Prerequisite steps:

  1. Download the Azure cloud-init.yaml file from Create, configure and download a Collector. You will use this file during Azure virtual-machine deployment.

Follow Microsoft documentation to create an Azure virtual machine:

Apply the following adjustments while following the Microsoft documentation:

  1. Under the Basics tab, select Ubuntu Server 22.04 LTS as the image.
  2. Under the Basics tab, select a suitable size that meets the Minimum Virtual Machine Requirements.
  3. Under the Disks tab, add one data disk of at least 500 GiB, sized in accordance with the Minimum Virtual Machine Requirements.
  1. Under the Advanced tab, paste the contents of cloud-init.yaml into the Custom data field.

NTT Smart Data Platform (SDPF)

Prerequisite steps:

  1. Download the SDPF cloud-init.yaml file from Create, configure and download a Collector. You will use this file during instance creation.

Follow NTT documentation to create a server instance:

Apply the following adjustments while following the NTT documentation:

  1. When selecting the image, select the latest Ubuntu 24.04 official image.
  2. When selecting compute series and size, select a suitable specification that meets the Minimum Virtual Machine Requirements.
  3. Add a separate data disk of at least 500 GB, sized in accordance with the Minimum Virtual Machine Requirements.
  1. When selecting the logical network, ensure that it fulfils the Connectivity required for the Collector. This typically requires an Internet Gateway, logical network, subnet, and potentially firewall rules that allow the Collector’s required outbound connectivity.
  2. In the Post-install script field, select Direct Input and paste the contents of the cloud-init.yaml file.

Deleting a Collector

To delete a Local Collector:

  1. In the SamurAI Portal, select Telemetry and then Collectors.
  2. Select the relevant Collector.
  3. On the right side of the relevant Collector, select More Options () and then select Delete Collector.
  4. Review the warning. To confirm the destructive action, enter DELETE and select Delete Collector.

Replacing a Collector

If a Local Collector virtual machine is lost because of corruption or damage, such as a major storage failure, delete the existing Collector in the SamurAI Portal, discard the old virtual-machine image, and create a new Collector by following the installation process.

What’s next?

You have now deployed and configured your Local Collector.

Refer to Local Collector Details for information about validating Collector status and additional configuration.

3 - Local Collector Details

Validate Collector Status

  1. Click Telemetry and select Collectors from the main menu

  2. Select the relevant Collector from the presented list

  3. View Status

IndicatorStatusDescription
PendingCollector components installing / provisioning or awaiting status
UnknownThe SamurAI platform is unable to determine a status
OKHealthy
WarningWarning status will be displayed if the Collector is experiencing any issues e.g components are experiencing problems
CriticalCritical status will be displayed and an email notification will be sent to registered users (by default) if the SamurAI platform cannot communicate with the Collector

After you provision a Collector VM and start it, it will go through a process of installing updates and modules specified in the configuration ISO file which you downloaded. The time taken for this process is dependent on factors like the speed of the hardware you are running the Collector on and connectivity to the repositories that it downloads updates from. In some cases this process can take around 30 minutes.

If you have any problems, please submit a ticket via the SamurAI Portal.

Collector Email Notifications

By default email notifications are enabled. The SamurAI platform sends email notifications to registered users when a Collector is reported as Critical (e.g. the SamurAI platform cannot communicate to the Collector) however this is customizable by users for any Collector status.

Enable or Disable Email Notifications

  1. Click on More Options () to the right of the table
  2. Select Notifications
  3. Toggle the setting to enable or disable by selecting the bell icon. Alternatively you can select the default setting
  4. Click Save

You can also achieve this per individual Collector by:

  1. Click on More Options () to the left of the Collector
  2. Select Notifications
  3. Toggle the setting to enable or disable by selecting the bell icon. Alternatively you can select the default setting (send notification).
  4. Click Save

What’s next?

The next step is to start configuring integrations which will allow the SamurAI platform to start receiving your telemetry data.

Select Integrations Overview for more information on integrations and where to start.

If you require high availability for your collector, this can be achieved using the capabilities of your virtualization platform.