Deploy the ExtraHop Explore Appliance in AWS
In this guide, you will learn how to launch the ExtraHop Explore appliance AMI in your Amazon Web Services (AWS) environment, and join multiple Explore appliances to create an Explore cluster.
System requirements
Your environment must meet the following requirements to deploy a virtual Explore appliance in AWS:
- An AWS account
- Access to the Amazon Machine Image (AMI) of the ExtraHop Explore appliance
- An Explore appliance product key
- An AWS instance type that most closely matches the Discover appliance VM size, as
follows:
Appliance Recommended Instance Types EXA 5100v m4.2xlarge (8 vCPU and 32 GB RAM) m4.4xlarge (16 vCPU and 64 GB RAM)
- A datastore size between 200 GB and 1.2 TB for the m4.2xlarge instance type or between 200 GB and 2.5 TB for the m4.4xlarge instance type.
Important: | If you want to deploy more than one ExtraHop virtual appliance, create the new instance with the original deployment package or clone an existing instance that has never been started. |
Create the Explore instance in AWS
Before you begin
The Amazon Machine Images (AMIs) of ExtraHop appliances are not publicly shared. Before you can start the deployment procedure, you must send your AWS account ID to support@extrahop.com. Your account ID will be linked to the ExtraHop AMIs.Configure the Explore appliance
After you obtain the IP address for the Explore appliance, log into the Explore Admin UI through the following URL: https://<explore_ip_address>/admin and complete the following recommended procedures.
Create an Explore cluster
If you are deploying more than one Explore appliance, join the appliances together to create a cluster. For the best performance, data redundancy, and stability, you must configure at least three Explore appliances in an Explore cluster.
In the following example, the Explore appliances have the following IP addresses:
- Node 1: 10.20.227.177
- Node 2: 10.20.227.178
- Node 3: 10.20.227.179
You will join nodes 2 and 3 to node 1 to create the Explore cluster.
Important: | Each node that you join must have the same configuration (physical or virtual) and ExtraHop firmware version. |
Connect the Explore appliance to Discover and Command appliances
After you deploy the Explore appliance, you must establish a connection from all ExtraHop Discover and Command appliances to the Explore appliance before you can query records.
Important: | If you have an Explore cluster of three or more Explore nodes, connect the Discover appliance to each Explore node so that the Discover appliance can distribute the workload across the entire Explore cluster. |
Note: | If you manage all of your Discover appliances from a Command appliance, you only need to perform this procedure from the Command appliance. |
Next steps
Important: | If you only deployed a single Explore appliance, after you connect to your Discover or Command appliance, you must log into the Admin UI on the Explore appliance and set the 0. | to
Send record data to the Explore appliance
After your Explore appliance is connected to all of your Discover and Command appliances, you must configure the type of records you want to store.
Thank you for your feedback. Can we contact you to ask follow up questions?