Single Master, Multiple Workers, and a High-availability Database

In this scenario, which deploys Intelligence with high availability on the ArcSight Database, you have a single master node connected to three worker nodes and a cluster for the ArcSight Database. This scenario supports an environment with modest EPS and minimal number of nodes. However, it allows for futher scaling with multiple worker nodes. Each worker node runs on a separate, dedicated, connected host. All nodes have the same operating system. The Kubernetes cluster for Intelligence includes Fusion, which provides ArcSight SOAR, and Transformation Hub.

If this scenario resembles your intended deployment, you might want to use the example-install-config-intelligence-scale_db.yaml config file with the ArcSight Platform Installer. For more information about the yaml files, see Using the Configuration Files in the Administrator's Guide for ArcSight Platform.

 

Diagram of this Scenario

Figure3. Example deployment of Intelligence and Recon

 

Characteristics of this Scenario

This scenario has the following characteristics:

 

Guidance for Node Configuration

You need a minimum of nine physical or VM environments: three dedicated master nodes, three or more dedicated worker nodes, and a database cluster. You also need a customer-provisioned, highly-available NFS server (External NFS) and an SMTP server.

The following table provides guidance for deploying the Intelligence across multiple nodes to support a medium workload.

Node Name Description RAM CPU Cores Disk Space Ports
Master Node

masternode1.yourenterprise.net

OMT Management Portal

(Optional) Fusion

256 GB 32 5 TB

OMT Management Portal

Kubernetes

NFS

Database Nodes 1-3

databaseNN.yourenterprise.net

Database 192 GB 24 28 TB Database
Worker 1

workernode1.yourenterprise.net

Intelligence

Fusion

Transformation Hub

256 GB 32 5 TB

ArcMC

Intelligence

Kubernetes

Transformation Hub

Worker 2

workernode2.yourenterprise.net

Intelligence

Fusion

Transformation Hub

256 GB 32 5 TB

ArcMC

Intelligence

Kubernetes

Transformation Hub

Worker 3

workernode3.yourenterprise.net

Fusion

Intelligence

Transformation Hub

256 GB 32 5 TB

ArcMC

Intelligence

Kubernetes

Transformation Hub