...
The Snare Central is capable of running on a variety of hardware configurations, from laptops, right up to Linux partitions on mainframe systems and VMs. Hardware requirements are significantly dependent on the volume of audit received by the Snare Central, and the type and number of audit objectives defined. As an appliance-style solution, expanding storage post-install is not a supported option. supported, however, It is therefore recommended that storage allocation is sized with a view towards long term requirements.
However, in order for the Snare Central to be in a supported configuration, the following requirements MUST be followed. There should be no deviations from the specifications listed below.
Info | ||
---|---|---|
| ||
This configuration may also be appropriate for sites with a medium to large number of source systems, that just want to use the Snare Central for the reflector functionality, and do not require any local reporting or data analysis. Reflector-only sites with high volumes of incoming data, or a count of source agents that is in the upper quarter of the 'larger configuration maximum, may need to increase the CPU and memory capacity to cope with the additional load. |
...
Info | ||
---|---|---|
| ||
Moderate environment up to 2,000 systems (<= 5,000 EPS)
For large to very large environments please contact your Snare Sales representative. |
...
Info | ||
---|---|---|
| ||
Where Snare Central is used just for Agent Management then the disk space requirements can be reduced as the system is not collecting any logs
Note: If there is less than 300GB 350GB of disk allocated to the system, it will default to a single partition AMC configuration. Only environments using 300GB 350GB or more will use the new disk layouts as per Appendix B. |
...