Skip to main content
Migration Notice
We're migrating documentation from the old portal into this one. Some things may look a little different or out of place in the meantime — we know, and we're working to get it right. If something's unclear or doesn't look right, let us know.
Version: 2.15.0

Before You Begin

Before installing the Threat Hunting module, ensure you have the necessary infrastructure, gather required configuration details, and review any version-specific requirements. This preparation will help ensure a smooth installation process.

Additional VM for Threat Hunting

An additional VM is required to install our new Threat Hunting feature.

Prerequisites​

  • ECA and Eyeglass system

    ECA Setup

    Working ECA and Eyeglass with configured nodes. See ECA VM Guide for setup help.

  • ML Module server

    Important

    The Threat Hunting module is currently distributed as an OVA package and is supported only on VMware-based virtualization platforms.

    Support for additional hypervisors is planned and will be introduced in future releases as part of our product roadmap.

    ML Server Specs

    Server with 8 CPU cores, 48GB RAM, 300GB storage (minimum). See the ML VM setup instructions section.

    For detailed system requirements and network latency considerations, refer to the Machine Learning VM section in the ECA VM Guide.

Required Configuration Details​

Before starting the installation, gather these essential connection and authentication parameters:

Commands to Run on the Threat Hunting VM​

Required InformationDescriptionHow to Obtain
ML module IP address and portConnection details for ML serverRun ip addr show to get the IP address. The port is specified during installation.

Commands to Run on ECA Node1​

Required InformationDescriptionHow to Obtain
ECA node IP addressesAll ECA server IPsSee the ECA Guide - run ecactl cluster exec hostname -I to list all node IPs
Kafka connection infoStreaming data service detailsRun ecactl cluster exec docker exec kafka cat ./config/server.properties | grep listeners= on ECA master to get Kafka node hostnames
ECA public keyPublic key the module uses to authenticate with the ECARun cat /opt/superna/eca/data/common/.secure/rsa/isilon.pub on an ECA node. Paste it as a single line, without the BEGIN/END markers.

Commands to Run on Eyeglass/SCA VM​

Required InformationDescriptionHow to Obtain
Eyeglass server IPEyeglass management server addressCheck your Eyeglass deployment documentation or run hostname -I on the Eyeglass VM
Appliance IDPlatform identifier for EyeglassDisplayed directly in License Management under Inventory (with a Copy Appliance ID button), or run igls admin appid on the Eyeglass server
Eyeglass API tokenToken the module uses to authenticate with EyeglassIn the Eyeglass UI, open Integrations and select the API Tokens tab.

Values You Choose or Obtain from Your Team​

Required InformationDescriptionHow to Obtain
Database and dashboard passwordsclickhouse_pass, postgres_admin_pass, superset_admin_user_pass, and superset_secret_keyYou choose these. Change every default before production use. See Configure Installation.
Network settings for the VMManagement IP, netmask, gateway, DNS, and NTPYour network team

System Requirements and ML VM Installation​

warning

Ensure your system meets all requirements before beginning the automated installation. Insufficient resources may cause installation failure or performance issues.

Minimum Version: Version 1.2.0 or higher

Hardware Requirements:

  • CPU: 8 cores minimum
  • RAM: 48 GB minimum
  • Storage: 300 GB minimum

Software Prerequisites:

  • Operating System: OpenSUSE Linux
    • You need to deploy an OpenSUSE VM downloaded from the Superna software downloads page: https://support.superna.net/
    • Name: Superna Kubernetes OVF
    • Version: latest
  • Eyeglass: Version 2.14.1 or higher with ECA cluster configured
  • Administrative Access: Root/sudo privileges on the installation server

Network Ports:

  • 9092 (TCP): Threat Hunting VM to every ECA node (Kafka)
  • 30443 (TCP): Admin browser to the Threat Hunting VM (Superset dashboards and health check)

For details, see Network Ports.

Download Requirements​

You have to download the following components from the Superna software downloads page: https://support.superna.net/.

  • Threat Hunting installer: Required for module deployment and automation
  • Version: latest