Eyeglass Deployment
Overview
Eyeglass is the management and control plane for Data Security. It is deployed as a single appliance VM, separate from the ECA cluster it manages — it licenses and registers each ECA, receives detected threats and health signals from it, and executes the configured response (lockout, snapshot, notification) against the affected PowerScale or ECS cluster.
Unlike the ECA cluster, Eyeglass is not deployed as a multi-node cluster — there is no cluster topology or node-count scaling decision to make for Eyeglass itself. For that reason, this page does not have a "sizing by environment size" table the way ECAs does; the single appliance size below covers all Data Security deployment sizes.
Eyeglass VM Sizing
The Eyeglass appliance requires the following specifications:
- vCPU: 4 vCPU
- RAM: 24 GB RAM
- Disk: 172 GB total (52 GB OS disk + 120 GB data disk)
- Hosts: 1 host
These figures are fixed regardless of ECA cluster size — see the Design Guide if you need to plan sizing for the ECA cluster or Threat Hunting ML VM alongside Eyeglass.
Platform Requirements
- Virtualization: VMware vSphere 6.0 ESX host or higher, Microsoft Hyper-V (VHDX format), or Nutanix AHV.
- vCenter: vCenter 7 or vCenter 8, if deploying on VMware.
- Network latency: Latency between the administration PC and the Eyeglass VM GUI must be less than 15 ms (measured by ping).
- Authentication: An Active Directory (AD) authentication provider must be available in the system zone for Role-Based Access Control (RBAC) and SID-to-user resolution API requirements.
- Browser: Google Chrome is required (must support WebSockets); Internet Explorer is not supported; third-party cookies must not be disabled.
See Pre-Requisites for the full platform compatibility and system requirements list.
Licensing
The Eyeglass appliance requires one of the following license types, depending on which Data Security capabilities you are deploying: Data Security Agent Licenses, Easy Auditor Agent Licenses, or Performance Auditor Licenses. Each writable PowerScale or ECS cluster you plan to monitor requires its own agent license, assigned through the Eyeglass License Manager — see Pre-Requisites — Licensing.
Steps to add Eyeglass licenses
- Verify compatibility — ensure Eyeglass is deployed or upgraded to the compatible release version for the ECA release being installed.
- Log in to Eyeglass — access the Eyeglass interface.
- Open License Management — open Inventory → License Management.
- Download the license key — follow the instructions to download the license key using the email token provided with your purchase.
- Upload the license key — upload the license key zip file obtained in the previous step. The page refreshes automatically once uploaded.
- Open License Management again — after the page refreshes, reopen Inventory → License Management.
- Set license status — open Inventory → Manage Devices. For each cluster you want to monitor with Data Security or Easy Auditor, set the license status to User Licensed. For clusters that should not be licensed, set the status to Unlicensed — this prevents licenses from being consumed by unintended clusters.
A system alarm is raised if more writable clusters are detected in the audit event stream than there are agent licenses assigned. Plan license counts for all writable clusters you intend to onboard, including future additions, before deployment.
Because Eyeglass is a single, non-clustered appliance, there is no placement/topology decision analogous to the ECA cluster's centralized-vs-remote-Mini-ECA choice — the license and sizing information above is the complete deployment picture for Eyeglass itself.
See also
- Pre-Requisites — platform compatibility, system requirements, and licensing.
- Design Guide — ECA cluster and Threat Hunting ML VM sizing to plan alongside Eyeglass.
- Eyeglass, ECA, and Mini-ECA Installation — full license activation and deployment steps.
- Deployments — ECAs, Mini-ECAs, and Threat Hunting ML VM deployment topics.