This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

Requirements

    What you need to get started

    • Access to the SamurAI Portal and your specific tenant.
    • A supported deployment platform for the Local Collector. Supported hypervisors and cloud platforms are listed below.
    • A virtual machine that meets the minimum virtual machine requirements.
    • The required network changes to meet the Collector connectivity requirements.
    • A static IP address for the Collector and DNS server IP addresses, unless you use DHCP.
    • Access to the products where you need to make the changes described in the relevant integration guide.

    Supported hypervisors

    HypervisorSupported version or requirement
    VMware ESXiESXi 8.x and ESXi 9.x
    Microsoft Hyper-VHyper-V 2016 and later; deploy the Local Collector as a Generation 2 virtual machine.
    Proxmox Virtual EnvironmentProxmox VE 8.4.1 and later.
    KVM-based environmentsKVM environments that support UEFI virtual machines and can import the Local Collector KVM bundle.

    Supported cloud platforms

    PlatformSupported instance types or requirements
    Amazon EC2Nitro-based instances using HVM virtualization.
    Azure Virtual MachineUbuntu Server virtual machines that meet the minimum requirements.
    NTT Smart Data Platform (SDPF)Ubuntu Server instances that meet the minimum requirements.

    Minimum virtual machine requirements

    ResourceRequirement
    CPU2 vCPU
    Disk500 GB dedicated data disk for spooling, in addition to the operating-system disk.
    Memory4 GB RAM

    Connectivity required for the Collector

    The Collector requires connectivity to the resources listed below. Update security controls, such as firewall rules, proxy settings, and DNS configuration, as needed to allow the required communications.

    FunctionProtocolPortSourceDestinationDetails
    Enrolment, TelemetryTCP443Collector*.*.security.ntt

    nttsecurity.io
    .nttsecurity.io
    .*.nttsecurity.io

    samurai-xdr-prod-westeurope-xgliuoit.azure-api.net
    All regular backend communication, telemetry
    Remote ManagementTCP443Collectorra.cto.nttsecurity.io

    deb.releases.teleport.dev

    apt.releases.teleport.dev
    Used for remote administration of Collector (this is not mandatory and used when troubleshooting)
    NTPUDP123CollectorClient infrastructure (NTP server(s)) if configured in SamurAI Portal

    OR

    0.ubuntu.pool.ntp.org

    1.ubuntu.pool.ntp.org

    2.ubuntu.pool.ntp.org

    3.ubuntu.pool.ntp.org
    Time synchronization
    DNSUDP53CollectorClient infrastructure (DNS server(s)) or external DNS servers (based on your Collector configuration)Domain name resolution
    Ubuntu updatesTCP80, 443Collector*.ubuntu.com

    api.snapcraft.io
    Ubuntu software repository
    Container ManagementTCP443Collectordocker.com

    *.docker.com (private container registry)

    docker.io (private container registry)

    *.docker.io (private container registry)
    Private container registry
    Amazon Cloud dependenciesTCP443Collector*.cloudfront.netAmazon CDN used by Collector API
    Log storageTCP443Collector*.s3.*.amazonaws.comAmazon Cloud storage (this is not mandatory and used when troubleshooting)
    Telemetry data(based on product - see Integration guide)Client ProductCollectorFrequent data transfer (based on product)

    What’s next?

    You now understand the supported deployment platforms, minimum virtual machine requirements, and required connectivity. Proceed to Deployment.