Calculations for the Central Node component deployed on the KVM virtualization platform
April 2, 2024
ID 265697
To deploy the Central Node component in a virtual infrastructure, you must install the KVM hypervisor based on the Debian GNU/Linux 12 operating system and using the QEMU 8.0.2 emulator.
When deploying the Central Node component in a virtual infrastructure, keep in mind the following limitations:
- It is possible to install the application with the installation files of the Ubuntu operating system only.
- Only the non-high-availability version of the application can be installed.
- You can only use the Sensor component deployed on the same server as the Central Node component.
- You can only connect a Sandbox component deployed outside the KVM virtualization platform on a physical server or on another supported virtualization platform.
- For each Central Node component deployed in a virtual infrastructure, a separate network interface must be used for receiving mirrored SPAN traffic.
- You cannot use the API to inform external systems about alerts generated by the application or the API for informing external systems about application events.
- Support for KVM virtualizations used in cloud solutions is not guaranteed.
The hardware requirements for the server with the Central Node component depending on the utilized functionality are presented in the table below.
Hardware requirements for the server with the Central Node component when using KEDR functionality
Maximum number of hosts with the Endpoint Agent component | Maximum number of email messages per minute | Maximum volume of traffic from SPAN ports on the server with the Central Node component (Mbps) | Minimum number of logical cores at 3 GHz | Minimum RAM (GB) |
---|---|---|---|---|
50 | 0 | 0 | 4 | 20 |
100 | 0 | 0 | 4 | 20 |
150 | 0 | 0 | 4 | 20 |
250 | 0 | 0 | 6 | 22 |
500 | 0 | 0 | 6 | 24 |
750 | 0 | 0 | 6 | 26 |
Hardware requirements for the server with the Central Node component when using KATA+KEDR functionality
Maximum number of hosts with the Endpoint Agent component | Maximum number of email messages per minute | Maximum volume of traffic from SPAN ports on the server with the Central Node component (Mbps) | Minimum number of logical cores at 3 GHz | Minimum RAM (GB) |
---|---|---|---|---|
100 | 1 | 20 | 6 | 26 |
250 | 5 | 50 | 6 | 28 |
500 | 30 | 100 | 10 | 31 |
750 | 30 | 100 | 12 | 31 |