Before You Begin
Before installing the Threat Hunting module, ensure you have the necessary infrastructure, gather required configuration details, and review any version-specific requirements. This preparation will help ensure a smooth installation process.
An additional VM is required to install our new Threat Hunting feature.
Prerequisites
-
ECA and Eyeglass system
ECA SetupWorking ECA and Eyeglass with configured nodes. See ECA VM Guide for setup help.
-
ML Module server
ImportantThe Threat Hunting module is currently distributed as an OVA package and is supported only on VMware-based virtualization platforms.
Support for additional hypervisors is planned and will be introduced in future releases as part of our product roadmap.
ML Server SpecsServer with 8 CPU cores, 48GB RAM, 300GB storage (minimum). See the ML VM setup instructions section.
For detailed system requirements and network latency considerations, refer to the Machine Learning VM section in the ECA VM Guide.
Required Configuration Details
Before starting the installation, gather these essential connection and authentication parameters:
Commands to Run on the Threat Hunting VM
| Required Information | Description | How to Obtain |
|---|---|---|
| ML module IP address and port | Connection details for ML server | Run ip addr show to get the IP address. The port is specified during installation. |
Commands to Run on ECA Node1
| Required Information | Description | How to Obtain |
|---|---|---|
| ECA node IP addresses | All ECA server IPs | See the ECA Guide - run ecactl cluster exec hostname -I to list all node IPs |
| Kafka connection info | Streaming data service details | Run ecactl cluster exec docker exec kafka cat ./config/server.properties | grep listeners= on ECA master to get Kafka node hostnames |
| ECA public key | Public key the module uses to authenticate with the ECA | Run cat /opt/superna/eca/data/common/.secure/rsa/isilon.pub on an ECA node. Paste it as a single line, without the BEGIN/END markers. |
Commands to Run on Eyeglass/SCA VM
| Required Information | Description | How to Obtain |
|---|---|---|
| Eyeglass server IP | Eyeglass management server address | Check your Eyeglass deployment documentation or run hostname -I on the Eyeglass VM |
| Appliance ID | Platform identifier for Eyeglass | Displayed directly in License Management under Inventory (with a Copy Appliance ID button), or run igls admin appid on the Eyeglass server |
| Eyeglass API token | Token the module uses to authenticate with Eyeglass | In the Eyeglass UI, open Integrations and select the API Tokens tab. |
Values You Choose or Obtain from Your Team
| Required Information | Description | How to Obtain |
|---|---|---|
| Database and dashboard passwords | clickhouse_pass, postgres_admin_pass, superset_admin_user_pass, and superset_secret_key | You choose these. Change every default before production use. See Configure Installation. |
| Network settings for the VM | Management IP, netmask, gateway, DNS, and NTP | Your network team |
System Requirements and ML VM Installation
Ensure your system meets all requirements before beginning the automated installation. Insufficient resources may cause installation failure or performance issues.
Minimum Version: Version 1.2.0 or higher
Hardware Requirements:
- CPU: 8 cores minimum
- RAM: 48 GB minimum
- Storage: 300 GB minimum
Software Prerequisites:
- Operating System: OpenSUSE Linux
- You need to deploy an OpenSUSE VM downloaded from the Superna software downloads page: https://support.superna.net/
- Name: Superna Kubernetes OVF
- Version: latest
- Eyeglass: Version 2.14.1 or higher with ECA cluster configured
- Administrative Access: Root/sudo privileges on the installation server
Network Ports:
- 9092 (TCP): Threat Hunting VM to every ECA node (Kafka)
- 30443 (TCP): Admin browser to the Threat Hunting VM (Superset dashboards and health check)
For details, see Network Ports.
Download Requirements
You have to download the following components from the Superna software downloads page: https://support.superna.net/.
- Threat Hunting installer: Required for module deployment and automation
- Version: latest