Deploy the ExtraHop Discover Appliance in AWS
The following procedure guides you through the deployment process of the ExtraHop Discover appliance AMI to monitor your Amazon Web Services (AWS) environment.
After you deploy the Discover appliance in AWS, configure remote packet capture (RPCAP) to forward traffic from remote devices to your virtual Discover appliance. For more information, see the Packet Forwarding with RPCAP guide.
System requirements
Your environment must meet the following requirements to deploy a virtual Discover appliance in AWS:
- An AWS account
- Access to the Amazon Machine Image (AMI) of the ExtraHop Discover appliance
- A Discover appliance product key
- An AWS instance type that most closely matches the Discover appliance VM size, as
follows:
Appliance Supported Instance Types EDA 1000v m3.large, c3.xlarge, c4.xlarge EDA 2000v m3.xlarge, c3.2xlarge, c4.2xlarge EDA 6100v c3.8xlarge, c4.8xlarge Note: C3 instance types deployed in a VPC will take advantage of Enhanced Networking capabilities. M3 instance types do not support Enhanced Networking.
Important: | If you want to deploy more than one ExtraHop virtual appliance, create the new instance with the original deployment package or clone an existing instance that has never been started. |
Create the ExtraHop instance in AWS
Before you begin
The Amazon Machine Images (AMIs) of ExtraHop appliances are not publicly shared. Before you can start the deployment procedure, you must send your AWS account ID to support@extrahop.com. Your account ID will be linked to the ExtraHop AMIs.Register an ExtraHop system in AWS
Complete the following steps to apply a product key supplied by ExtraHop Support in an AWS environment.
If you do not have a product key, contact your ExtraHop account team.
Tip: | To verify that your environment can resolve DNS entries for the
ExtraHop licensing server, open a terminal application on your Windows, Linux, or
Mac OS client and run the following
command:nslookup -type=NS d.extrahop.com If the name
resolution is successful, output similar to the following
appears:
Non-authoritative answer: d.extrahop.com nameserver = ns0.use.d.extrahop.com. d.extrahop.com nameserver = ns0.usw.d.extrahop.com. |
Thank you for your feedback. Can we contact you to ask follow up questions?