Deploy an ExtraHop sensor on Azure
The following procedures explain how to deploy a virtual ExtraHop sensor in a Microsoft Azure environment. You must have experience administering in an Azure environment.
An ExtraHop virtual sensor can help you to monitor the performance of your applications across internal networks, the public internet, or a virtual desktop interface (VDI), including database and storage tiers. The ExtraHop system can monitor application performance across geographically distributed environments, such as branch offices or virtualized environments through inter-VM traffic.
Before you begin
- You must have experience deploying virtual machines in Azure within your virtual network infrastructure. To ensure that the deployment is successful, make sure you have access to, or the ability to create the required resources. You might need to work with other experts in your organization to ensure that the necessary resources are available.
- You must have a Linux, Mac, or Windows client with the latest version of Azure CLI installed.
- You must have the ExtraHop virtual hard disk (VHD) file, available on the ExtraHop Customer Portal. Extract the VHD file from the downloaded .zip archive file.
- You must have an ExtraHop product key.
Important: | To ensure the best performance for initial device synchronization, connect all sensors to the console and then configure network traffic forwarding to the sensors. |
Deploy the sensor
Before you begin
The procedures below assume that you do not have the required resource group, storage account, storage container, and network security group configured. If you already have these parameters configured, you can proceed to step 6 after you log in to your Azure account to set Azure environment variables.System requirements
You must configure the following environmental parameters in Azure to deploy your ExtraHop virtual sensor:
- An Azure account.
- A Resource Group that holds related resources for the ExtraHop sensor.
- A geographic region where the Azure resources are located to sustain your virtual sensor.
- An Azure storage account that contains all of your Azure Storage data objects, including blobs and disks.
- A storage container where the ExtraHop sensor image is stored as a blob.
- A Standard_LRS storage SKU disk or four StandardSSD_LRS storage SKU disks to store ExtraHop sensor data.
- A network security group that contains security rules that allow or deny inbound network traffic to, or outbound network traffic from the ExtraHop sensor.
- A public or private IP address that enables access to the ExtraHop system.
VM requirements
You must provision an Azure instance size that meets the following requirements.
Sensor | Instance Type |
---|---|
EDA 1100v | Standard_A4_v2 (4 vCPU and 8 GiB RAM) |
EDA 6100v | Standard_D16_v3 (16 vCPU and 64 GiB RAM) |
EDA 6370v | Standard_D48s_v5 (48 vCPUs and 192 GiB RAM) |
Precision packet capture disk requirements
If your deployment includes precision packet capture, you must configure a packetstore disk that meets the following requirements.
Sensor | Disk storage SKU | Maximum size |
---|---|---|
EDA 1100v | Standard_LRS | 256 GiB |
EDA 6100v | Standard_LRS | 512 GiB |
EDA 6370v | Standard_LRS | 512 GiB |
Note: | Do not add a precision packet capture disk to EDA 6370v sensors if the Packet Forensics module is enabled; instead, add a packet forensics disk. |
Packet Forensics disk requirements
If your deployment includes global packet capture with the Packet Forensics module, you must configure packetstore disks that meet the following requirements.
Sensor | Disk storage SKU | Disk size (for each disk) | Number of disks |
---|---|---|---|
EDA 6370v | StandardSSD_LRS | 8192 GiB | 4 |
Note: | EDA 1100v and EDA 6100v sensors do not support the Packet Forensics module. |
Deploy the sensor
Before you begin
The procedures below assume that you do not have the required resource group, storage account, storage container, and network security group configured. If you already have these parameters configured, you can proceed to step 6 after you log in to your Azure account to set Azure environment variables.Add a disk for precision packet capture
If your sensor is licensed for precision packet capture, you must add a dedicated storage disk on the VM to store the packets.
Thank you for your feedback. Can we contact you to ask follow up questions?