Software Secure Workload
Activity Configure

Secure Workload Ingest

Secure Workload Ingest appliance is a software appliance that can export flow observations to Secure Workload from various connectors.

Specification

  • Number of CPU cores: 8

  • Memory: 8 GB

  • Storage: 250 GB

  • Number of network interfaces: 3

  • Number of connectors on one appliance: 3

  • Operating System: CentOS 7.9 (Secure Workload 3.8.1.19 and earlier), AlmaLinux 9.2 (Secure Workload 3.8.1.36 and later)

See important limits at Secure Workload Virtual Appliances for Connectors.


 

Each root scope on Secure Workload can have at most 100 Secure Workload Ingest appliances deployed.

Secure Workload Ingest appliance
Figure 1: Secure Workload Ingest appliance

Secure Workload Ingest appliance allows at most 3 connectors to be enabled on an appliance. There can be more than one instance of the same connector enabled on the same appliance. For the ERSPAN Ingest appliance three ERSPAN connectors are always automatically provisioned. Many of the connectors deployed on Ingest appliance collects telemetry from various points in the network, these connectors need to listen on specific ports on the appliance. Each connector is therefore bound to one of the IP address and the default ports on which the connector should be listening to collect telemetry data. As a result, each IP address is essentially a slot that a connector occupies on the appliance. When a connector is enabled, a slot is taken (thereby, the IP corresponding to the slot). And, when a connector is disabled, the slot occupied by the connector is released (thereby, the IP corresponding to the slot). See the Secure Workload Ingest appliance slots for how to ingest appliance maintains the state of the slots.

Secure Workload Ingest appliance slots
Figure 2: Secure Workload Ingest appliance slots

Allowed Configurations