User Tools

Site Tools


tips:trisul_installation

Trisul Installation

This article provides guidelines to help installing Trisul Network Anayltics in your system.

Trisul is a distributed monitoring system with a number of trisul-probe instances all reporting back to one or more trisul-hub. We first explain how you can install all components on a single box and then slowly expand to explore distributed installation.

There are three major ways to get data into Trisul. Click on each link for detailed instructions.

Live packet capture

  • Configure a Port Mirror (SPAN Port), use a Network Tap, or a Linux Inline Bridge.
  • Read Setup packet capture for Trisul.

Netflow from routers, switches

  • Configure your routers, switch to send Netflow, SFLOW, IPFIX or other similar flow information to Trisul.
  • Read Setup Netflow for Trisul.

Read PCAP dumps

  • Read PCAP files dumped by a third party program like tcpdump.
  • Read Process PCAP dumps with Trisul.

System Requirements

Computing requirements needed to run Trisul.

In Packet Capture mode

Single machine in the default Packet Capture Mode with typical small enterprise load of 50-200Mbps.

Bare Metal - 4 Core 3Ghz Intel i3/i5/i7/or Xeon class, 8GB RAM, 2×1Gb LAN. SATA or 10K SAS for PCAP storage.

Virtual Machine - 8 vCPU Cores, 12GB RAM, 2×1Gb LAN. VM Port Group mirror feature enabled to receieve the raw packets. VM is not recommended in Packet Capture mode when total load is greater than 500Mbps. Consider bare metal deployment.

In Netflow mode

Single machine in NETFLOW mode monitoring a router/switch with 1Gbps load.

Bare Metal - 4 Core 3Ghz Intel i3/i5/i7/or Xeon class, 8GB RAM, 2×1Gb LAN. SATA storage.

Virtual Machine - 6 Core 3Ghz Intel i3/i5/i7/or Xeon class, 8GB RAM, 2×1Gb LAN. SATA storage. Virtual Machine is preferred in Netflow mode for enterprise class load.

Operating System

Trisul is available on the following operating systems. Go to the Download Center to get access to the latest packages.

  • Ubuntu 18.04 LTS - 64-bits
  • Ubuntu 20.04 LTS - 64-bits
  • Ubuntu 22.04 LTS - 64-bits
  • CentOS 7.x - 64-bits
  • RHEL/Oracle 8 - 64-bits
  • RHEL/Oracle 9 - 64-bits
  • Docker - on any host O/S

If you have a distributed system, Trisul Probes and Trisul Hubs can be installed on different O/S.

tips/trisul_installation.txt · Last modified: 2024/05/21 12:17 by vignesh