Deploying Logpoint AMI

Selecting an AMI and Launching Logpoint Instances

Securing AWS Infrastructure for Launching Logpoint Instances

To launch the Logpoint instances securely in the AWS environment, we recommend you enable EBS encryption and launch all instances from the EBS-encrypted AMI, including the root volume.

For enhanced security, we recommend you implement IMDSv2. To transition from IMDSv1 to IMDSv2, follow the AWS Documentation.

Enabling EBS Encryption and Launching Instances from the EBS-encrypted AMI

We recommend you enable EBS encryption and launch all instances from the EBS-encrypted AMI, including the root volume.

  1. Log into the AWS management console.

  2. Go to Services >> EC2.

  3. Select AMIs under Images.

    _images/LP_Cloud_AWS_EC2_AMIsSelected.png

    Selecting AMIs

  4. Select Private Images from the drop-down.

    _images/LP_Cloud_AWS_EC2_AMIs_PrivateImagesSelected.png

    Selecting Private Images

  5. Select the Logpoint AMI and click Copy AMI from the Actions drop-down.

    _images/LP_Cloud_AWS_EC2_AMIs_CopyAMI.png

    Copying AMI for encryption

  6. Select the Destination Region.

    _images/LP_Cloud_AWS_EC2_AMIs_ApplyingEncryption.png

    Applying EBS encryption

  7. Enter the Name and Description for the encrypted AMI.

  8. Select Encryption and select the Master Key for encryption.

  9. Once you are redirected to the AMIs page, select the Owned by me from the drop-down.

  10. Select the copied AMI and click Launch.

Launching Instance without enabling EBS Encryption

  1. Log into the AWS management console.

  2. Go to Services >> EC2.

  3. Select AMIs under Images.

    _images/LP_Cloud_AWS_EC2_AMIsSelected.png

    Selecting AMIs

  4. Select Private Images from the drop-down.

    _images/LP_Cloud_AWS_EC2_AMIs_PrivateImagesSelected.png

    Selecting Private Images

  5. Select the Logpoint AMI.

  6. Click Launch.

Choosing an Instance Type

_images/LP_Cloud_AWS_EC2_AMIs_InstanceType.png

Selecting an Instance Type

  1. Choose an Instance Type from the list. The minimum configuration is t2.xlarge type with 4 CPUs and 16 GiB memory.

  2. Click Next: Configure Instance Details.

Configuring the Instance Details

_images/LP_Cloud_AWS_EC2_AMIs_InstanceDetails.png

Configuring the Instances Parameters

  1. Enter the Number of instances.

  2. Deselect the Purchasing option. It is not relevant.

  3. Select a Virtual Private Cloud (VPC) Network to host Logpoint AMI. You can create a new VPC or select from the available ones.

  4. Select the Subnet for your instances from the selected VPC. You can use the existing subnet or create a new one.

  5. Select Auto-assign Public IP if you want to make your instances accessible from the Internet.

  6. Select Placement group to launch the instances in a placement group. The placement group determines how instances are placed on the underlying hardware. All the placement groups function under one of the following strategies:

    • Cluster — clusters the instances into a low-latency group in a single Availability Zone.

    • Spread — spreads the instances across the underlying hardware. You can either add the instance to an existing placement group by selecting Add to existing placement group or create a new placement group by selecting Add to a new placement group.

      • If you select Add to existing placement group, choose one of the available placement groups from the drop-down.

      • If you select Add to a new placement group, add a new placement group by specifying a Name and Placement group strategy.

  7. Choose a Capacity Reservation option. You can choose either Open, Target by group, Target by ID, or None.

  8. Select a Domain join directory to join the Logpoint instance to a directory defined in the AWS Directory Service.

  9. Specify the IAM role for the instances if required. Identity and Access Management (IAM) lets you specify permissions granted to each AWS resource.

  10. Select an appropriate Shutdown behavior for the instances. If you select Stop, the instances stop running, whereas, if you select Terminate, the instances are permanently deleted.

  11. Select Stop - Hibernate behavior to enable hibernation in the instance.

  12. Enable termination protection to receive a confirmation message before terminating the instances.

  13. Select Monitoring to analyze instance metrics in detail using Amazon CloudWatch.

    By default, you have access to basic monitoring, which allows you to view metrics every five minutes. The CloudWatch detailed monitoring allows you to view the metrics in the one-minute interval.

  14. Select a Tenancy infrastructure to run your instances.

  15. Select Add an Elastic Inference accelerator to enable cost-efficient hardware acceleration.

  16. Select Unlimited credit specification to allow the Logpoint instances to exceed the CPU utilization baseline whenever required.

  17. Specify Amazon EFS File systems to mount to the Logpoint instance.

  18. Leave the Network interfaces and Advanced Details settings as they are.

  19. Click Next: Add Storage.

Adding Storage

_images/LP_Cloud_AWS_EC2_AMIs_AddStorage.png

Adding Storage to Instances

  1. Specify the storage device settings to launch the instance. Enter 150 GiB volume to install and run a Logpoint instance.

  2. Click Next: Add Tags.

Adding Tags

_images/LP_Cloud_AWS_EC2_AMIs_AddTags.png

Adding Tags to Instances

  1. Enter the tags to be applied to the instance. The tags help you distinguish the instances and volumes when required.

  2. Click Next: Configure Security Group.

Configuring Security Groups

We recommend opening the required ports in the network Access Control List (ACL) and configure security groups to launch Logpoint instances securely.

_images/LP_Cloud_AWS_EC2_AMIs_SecurityGroups.png

Configuring Security Groups

  1. In the Configure Security Group, select Create a new security group to set all the firewall rules that control the traffic for your Logpoint instances.

    Port

    Protocol

    Service

    514

    TCP

    Syslog Collector

    6514

    TCP

    Syslog Collector SSL

    6161

    TCP/UDP

    Snare Collector

    6162

    TCP/UDP

    Snare Collector

    6343

    UDP

    SFlow Collector

    21

    TCP

    FTP

    162

    TCP

    SNMP Trap Collector

    443

    TCP

    Web Service

    9001

    UDP

    EMC Collector

    7996/7997/7998/7999

    TCP

    Logpoint Agent Collector

  2. Click Review and Launch.

Review

_images/LP_Cloud_AWS_EC2_AMIs_Review.png

Review and Launch

Review all the configurations and click Launch.

Obtaining a Key Pair

After you click Launch, a key pair is required to establish an SSH connection with Logpoint. To obtain a key pair, you can either Choose an existing key pair or Create a new key pair from the drop-down menu.

If you choose to Create a new key pair,

  1. Enter a Key pair name.

  2. Click Download Key Pair.

_images/LP_Cloud_AWS_EC2_AMIs_KeyPairNew.png

Creating a new key pair

  1. Click Launch Instances.

If you Choose an existing key pair,

  1. Select a key pair from the list of the available key pairs.

  2. Read the confirmation message and agree with the terms.

_images/LP_Cloud_AWS_EC2_AMIs_KeyPairChoose.png

Choosing an existing key pair

  1. Click Launch Instances.


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support