Install a vLC in an AWS environment
You can install an Arctic Wolf® Virtual Log Collector (vLC) in an AWS environment.
Note:
- vLCs do not support all Amazon Web Services (AWS)® service logs, including AWS Directory Service logs. Generally, if the structure of a log is not a single line of text, it is not supported.
- vLCs do not support auto-scaling in AWS.
- For more information about AWS best practices, see Best practices of Amazon EC2 and Security best practices for your VPC.
- During connectivity tests, appliances may communicate with external IP addresses behind a cloud service that Arctic Wolf hosts.
These actions are required:
- Make sure you have the appropriate Arctic Wolf permissions to install the appliance. Contact your Concierge Security® Team (CST) at security@arcticwolf.com to identify who in your organization has these permissions.
- Add all necessary IP addresses, ports, and services to your allowlist for full appliance functionality.
Tip: To see the IP addresses that you must allowlist, sign in to the Arctic Wolf Unified Portal, click , and then view the IP addresses in the section for your product.
- If you rate-limit the appliance with Quality of Service (QoS), remove this for best performance.
- If your firewall provides SSL/TLS inspection, do not do this inspection on the appliance management IP address.
- If you use an application proxy or layer 7 filter on your firewall, allow outbound traffic for the appliance management IP address.
- Optional: Configure two vLCs in a high availability environment. For more information, see Configure two vLCs in a high availability AWS environment.
- Configure log forwarding. For more information, see Syslog forwarding.
Provide AWS account IDs to Arctic Wolf
Note: It can take up to 24 hours for the vLC AMI to become visible.
Create a vLC instance
Configure network settings for the vLC instance
Configure security group rules for the vLC instance
Launch and verify the EC2 instance
Connect to the serial console
- If you have not used the serial console before, complete these steps to configure serial console access:
- Click .
- In the Account Attributes section, select EC2 Serial Console.
- In the EC2 Serial Console section, select the Allow checkbox.
- Click Update.
- In the EC2 management console, select Instances, and then enter the vLC instance ID.
- Click .
Configure the vLC
Use the serial console to configure the vLC. For more information on using the serial console, see Serial console.
Activate the vLC
Note: Only the user who configured the vLC can activate the vLC.