Virtual Log Collector Installation in a VMware vSphere Environment

Updated Sep 13, 2023

Install a vLC using VMware vSphere

The Arctic Wolf® Virtual Log Collector (vLC) is a virtualized log collector for syslog. Arctic Wolf Managed Detection and Response (MDR) uses one or more vLC deployments to monitor events in your network and identify potential threats. You can use a vLC independently or with Arctic Wolf network sensors.

Each vLC virtual machine (VM) supports one network interface. If you need additional network interfaces, you must deploy additional vLC VMs.

If you are deploying multiple vLC instances, we recommend reusing the OVA file. However, you must repeat the installation and activation process for each vLC.

Cloning a vLC instance is not supported, because this method introduces operational errors in both the original vLC and the cloned instance.

Requirements

Before you begin

Steps

  1. Download the vLC image.
  2. Deploy the vLC.
  3. Verify that the vLC deployed correctly.
  4. Configure the vLC.
  5. Activate the vLC.

Step 1: Download the vLC image

Note: The virtual appliance image file must be downloaded on or after June 14, 2023. For appliance images downloaded prior to June 14, 2023, see Legacy vLC Installation.

  1. Sign in to the Arctic Wolf Portal.
  2. Click Account > Downloads.
  3. In the Virtual Network Appliances section, click Download Virtual Network Appliance to start the OVA file download.

    Tip: If your browser downloads the OVA file in .ovf format, rename the file to change the file extension to .ova.

Step 2: Deploy the vLC

  1. Sign in to your vSphere client.

  2. Right-click your resource pool, and then click Deploy OVF Template.

  3. On the Select an OVF template page:

    1. Select Local file.
    2. Click UPLOAD FILES.
    3. Select the downloaded OVA file, and then click Open.
    4. Click Next.
  4. On the Select a name and folder page:

    1. In the Virtual machine name field, enter a name for the vLC.
    2. Select the location for the virtual machine, and then click Next.
    3. Click Next.
  5. On the Select a compute resource page:

    1. Select a destination compute resource.
    2. Click Next.
  6. On the Review details page, click Next.

  7. On the Configuration page, select vLC.

  8. On the Select storage page:

    1. (Optional) Select Encrypt this virtual machine. See the VMware vSphere product documentation for steps to encrypt an existing virtual machine or virtual disk.

      Tip: While optional, Arctic Wolf strongly recommends that you encrypt the vLC to ensure that all data stored and flowing through the appliance has an additional layer of protection.

    2. Select the storage location for the configuration and disk files, and then click Next.

  9. On the Select networks page:

    1. Select the appropriate Destination Network.

    2. Click Next.

  10. On the Ready to complete page, click Finish.

    Note: The OVA image may take some time to upload. In the vSphere Client, you can check the progress of the upload on the Recent Tasks tab.

Step 3: Verify that the vLC deployed correctly

  1. If the vLC power is off, right-click your virtual machine in the vSphere Client, and then click Power > Power On.
  2. Check if the vLC VM power is on.
  3. Verify that the VM IP address is reported in the VM summary.

Step 4: Configure the vLC

  1. In the vSphere web UI, right-click your virtual machine, and then click Power > Power On.

  2. Right-click your virtual machine, and then click Console > Open Console.

  3. When prompted, press Enter three times to initiate the serial console session.

  4. At the Select an option to configure your management interface with prompt, select DHCP or enter a static IP address for the vLC management interface.

    Note: If you select DHCP, you must use a DHCP reservation to prevent log collection and connection errors.

  5. Click Next.

  6. At the Use a proxy? prompt, do one of these actions:

    • If your vLC traffic needs to go through a proxy server, select Yes, and then configure these fields:
      • Server IP address — Enter the proxy server IP address for your appliance.
      • Server port — Enter the proxy server port.
    • If your vLC traffic does not need to go through a proxy server, select No.
  7. Click Next.

  8. At the Do you want to verify your network connection? prompt, select one of these options:

    • Yes

      A series of connectivity tests run.

    • No

  9. Click Next.

  10. At the Tell us about the application you are configuring prompt, configure these settings:

    1. In the Shorthand field, enter the shorthand name for the vLC.

    2. Select VLC.

  11. Click Next.

  12. When prompted, do one of these actions to connect the vLC to the Arctic Wolf Platform:

    • Using a mobile device — Scan the QR code displayed in the console window, and then follow the on-screen prompts.
    • Using a web browser — Enter the displayed URL into a web browser, and then follow the on-screen prompts.

    Note: QR codes expire after 15 minutes. A new code appears in the console if the QR code expires.

    After the vLC successfully connects to the Arctic Wolf Platform, a prompt replaces the QR code, asking you to go to the Arctic Wolf Appliance Management.

Step 5: Activate the vLC

Note: Only the user who performed the steps to configure the vLC can activate the vLC.

  1. In the Arctic Wolf Portal, click Account > Arctic Wolf Appliance Management.

  2. Locate the name or the serial number of the vLC you want to activate.

  3. In the Actions column, click Activate virtual appliance, and then click Activate Virtual Network Appliance when prompted.

    The console displays Appliance activation in progress, please wait.

  4. When prompted, press Enter three times to activate the console.

Reconfigure a vLC using VMware vSphere

  1. In the vSphere web UI, right-click your virtual machine, and then click Console > Open Console.
  2. When prompted, press Enter three times to initiate the serial console session.
  3. Change the required settings.

Uninstall a vLC using VMware vSphere

  1. Decommission the vLC:
    1. Sign in to the Arctic Wolf Portal.

    2. Click Account > Arctic Wolf Appliance Management

      A list of deployed virtual appliances appear on the Arctic Wolf Appliance Management page.

    3. Locate the short name or serial number of the vLC that you want to decommission.

    4. Under Actions, click Decommission Virtual Appliance, and then select Decommission Virtual Appliance when prompted.

  2. Turn off the vLC VM power.
  3. In the vSphere Client, select the vLC, and then click Delete from Disk.

See also