Install a vSensor using the Azure portal
You can install an Arctic Wolf® Virtual Sensor (vSensor) using the Microsoft Azure® web console.
Note:
- These steps only apply if you have a plan other than a Cloud Solution Provider (CSP) plan. If you have a CSP plan, see Install a vSensor using the Azure portal with direct share or Install a vSensor using the Azure portal with a manual upload (sign-in required).
- Some detections may not be available if sensors cannot see the relevant network traffic, including traffic flowing through different switches or unmonitored firewalls. Make sure that sensors are properly placed across all network egress points.
- During connectivity tests, appliances may communicate with external IP addresses behind a cloud service that Arctic Wolf hosts.
- The vSensor generates additional observations for any traffic that is not filtered or dropped by the upstream firewall. The Azure virtual network Terminal Access Point (TAP) mirrors the traffic from the source VM interface network interface controller (NIC) directly. You may want to deploy the vSensor behind a firewall.
These actions are required:
- Make sure you have the appropriate Arctic Wolf permissions to install the appliance. Contact your Concierge Security® Team (CST) at security@arcticwolf.com to identify who in your organization has these permissions.
- Add all necessary IP addresses, ports, and services to your allowlist for full appliance functionality.
Tip: To see the IP addresses that you must allowlist, sign in to the Arctic Wolf Unified Portal, click , and then view the IP addresses in the section for your product.
- If you rate-limit the appliance with Quality of Service (QoS), remove this for best performance.
- If your firewall provides SSL/TLS inspection, do not do this inspection on the appliance management IP address.
- If you use an application proxy or layer 7 filter on your firewall, allow outbound traffic for the appliance management IP address.
- Configure log forwarding. For more information, see Syslog forwarding.
Provide your Azure account information to Arctic Wolf
Create a vSensor instance
Create a network security group
Create inbound security rules
- In the side navigation, click .
- Create a virtual network Terminal Access Point (TAP) rule:
Attach a network interface
Create an interface to receive virtual network terminal access point (TAP) traffic.
Enable accelerated networking
Enable accelerated networking on the network interface you created in Attach a network interface.
Connect to the serial console
- In the side navigation, click Virtual machines.
- Select your VM.
- In the side navigation, click .
- Click .
Configure the vSensor
Use the serial console to configure the vSensor. For more information on using the serial console, see Serial console.
Activate the vSensor
Note: Only the user who configured the vSensor can activate the vSensor.