Deploy the ExtraHop Command Appliance in AWS

This guide explains how to launch the ExtraHop Command appliance AMI to monitor your Amazon Web Services (AWS) environment. You must have administrative access to AWS to launch a third-party AMI and an ExtraHop product key to complete these procedures.

Before you deploy the Command appliance, determine the optimal provisioning needs for your environment. For more information, see the Performance guidelines section.

Important:If you want to deploy more than one ExtraHop virtual appliance, do not clone an existing instance. Always start with the original deployment package when deploying additional instances.

Create the ExtraHop instance in AWS

  1. In a browser, type aws.amazon.com, and click My Account/Console.
  2. Select AWS Management Console.
  3. Sign in with your username and password.
  4. Click EC2.
  5. In the left navigation panel, under Images, click AMIs.
  6. Above the table of AMIs, change the Filter from Owned by Me to Public Images.
  7. In the Search AMIs… field, type ExtraHop.
  8. Select the checkbox next to the ExtraHop Command Appliance AMI, and click Launch.
  9. In the left navigation panel, click General Purpose and select m3.large.
  10. Click Next: Configure Instance Details.
  11. From the Network drop-down list, select Launch into EC2-Classic or select a VPC.
    You must launch the Command appliance in the same environment as the ExtraHop Discover nodes.
  12. Select Stop as the default shutdown behavior.
  13. Click the Protect against accidental termination checkbox.
  14. Optional: Click the IAM role drop-down list, and select an IAM role.
  15. Optional: If you want to configure two interfaces for VPC, scroll down to the Network Interfaces section and click Add Device to associate another interface with your instance.
    The default number of network interfaces is one. The two interfaces must be on two different subnets.
  16. Click Next: Add Storage.
  17. Accept the defaults and click Next: Tag Instance.
  18. In the Value field, enter a name for the instance.
  19. Click Next: Configure Security Group.
  20. On the Configure Security Group page, follow the procedure below to create a new security group or add ports to an existing group. If you already have a security group with the required ports for ExtraHop, you can skip this step.
    1. Select either Create a new Security Group or Select an existing security group. If you choose to edit an existing group, select the group you want to edit. If you choose to create a new group, type a name for the Security group and type a Description.
    2. From the Type drop-down list, select a protocol. Type the port number in the Port Range field.
    3. For each additional port, click the Add Rule button. Then, from the Type drop-down list, select a protocol, and type the port number in the Port Range field.
      The following ports and IP addresses must be opened for the ExtraHop AWS instance:
      TCP ports 22, 80, and 443 inbound to the Command appliance
      These ports must be open to download the installer and administer the ExtraHop system. If you cannot open port 80, you can copy the installer to each instance manually.
      IP addresses of the ExtraHop Discover nodes that are connected to the Command cluster
      After the Command appliance is launched, you must modify the security groups of the connected Discover nodes to allow traffic in from the Command appliance.
  21. Click Review and Launch.
  22. Scroll down to review the AMI details, instance type, and security group information, and then click Launch.
  23. In the pop-up window, from the first drop-down list, select Proceed without a key pair.
  24. Click the I acknowledge… checkbox and then click Launch Instance.
  25. Click View Instances to return to the AWS Management Console.
    When you return to the AWS Management Console, you can view your instance on the Initializing screen.
Located under the table, on the Description tab, is the IP address or hostname for the Command appliance.

Register an ExtraHop system in AWS

Complete the following steps to apply a product key supplied by ExtraHop Support in an AWS environment.

  1. In your browser, type the IP address of the ExtraHop appliance (https://<extrahop_management_ip>/admin).
  2. Review the license agreement, select I Agree, and click Submit.
  3. On the log in screen, type setup for the user name and the instance ID for the password.
    You can find the Instance ID on the Description tab of an instance selected on the Initializing screen. Type the string of characters that follow i- (but not i- itself), and then click Log In.
  4. Click Please apply license in Admin UI.
  5. Click Register.
  6. Enter the product key, and then click Register.
  7. Click Done.

Performance guidelines

The following table provides guidelines that can help you optimize the performance of the Command appliance. These guidelines are minimum requirements that you might need to adjust based on the size and needs of your environment.

Scalability ExtraHop Nodes 1-4 5-16 17-64 65 or more
Provisioning Requirements CPU Cores 2 4 8 16
RAM 4 GB 8 GB 16 GB 24 GB
Disk Total 44 GB
Networking Requirements One 1 Gbps Ethernet network port accessible on port 443
Published 2017-08-18 20:55