Use isto se
Capture traffic using Virtual Network TAP, deploy sensor VM with Bicep, and bridge network telemetry into the security platform.
- Audience
- Platform engineers, Azure administrators, security engineers
- Typical time
- 10 minutes
Guia público
Capture traffic using Virtual Network TAP, deploy sensor VM with Bicep, and bridge network telemetry into the security platform. Público: Platform engineers, Azure administrators, security engineers. Tempo típico de configuração: 10 minutes.
Capture traffic using Virtual Network TAP, deploy sensor VM with Bicep, and bridge network telemetry into the security platform.
Copy a working starter, run it in your environment, then come back here for the deeper rollout details.
Descarrega os ficheiros exatos usados neste guia ou executa o instalador de um só comando para os escrever localmente antes do deploy.
Creates the Azure Bicep template under `deploy/azure-network-sensor/` with the current platform API URL prefilled for VNet TAP-based network telemetry ingestion.
BLACKSHIELD_NETWORK_SENSOR_IMAGE=public.ecr.aws/blackshield-security/network-sensor:1.0.0 \
BLACKSHIELD_API_URL=https://api.blackshield.chaplau.com \
bash <(curl -fsSL https://blackshield.chaplau.com/source-bundles/azure-network-sensor.sh)
cd deploy/azure-network-sensor#!/bin/bash
# Create Azure Virtual Network TAP for network sensor
RESOURCE_GROUP="myResourceGroup"
VNET_TAP_NAME="network-sensor-tap"
az network vnet tap create \
--resource-group "$RESOURCE_GROUP" \
--name "$VNET_TAP_NAME"Use the guided steps below when you want to tailor the rollout, validate ownership, or expand the deployment safely.
Passo 1
Set up an Azure VNet TAP to duplicate traffic from production VMs to the sensor.
Como é o sucesso
Confirm mirrored traffic is flowing to the sensor NIC.
Passo 2
Use the source bundle on this page to download the Azure network sensor Bicep template and deploy it.
Como é o sucesso
The VM automatically retrieves the API key from Key Vault and starts the sensor container.
Passo 3
Confirm network telemetry is flowing into the platform.
Como é o sucesso
Verify flow to the platform within 5 minutes of traffic on the mirrored interfaces.
Keep your rollout moving with the next recommended step.
Revise e priorize achados