Hello I would like to build a Netwitness 11 test lab, so we can try it out and get familiar with the new features before moving to Netwitness 11 in live.
Can anyone let me know what the minimum requirements in terms of
- Number of Virtual Machines
- Specifications of those Virtual Machines in terms of CPU Cores, RAM and Storage
that would be needed.
It would only be very minimal logs and packet traffic.
Thanks in advance for your help.
Under normal circumstances, you'll need 6 VMs to do what you want to do:
- Analytics Server
- ESA
- Concentrator
- Log Decoder
- Packet Decoder
- Archiver
If you can dedicate 4 cores, 16GB of RAM, and 150GB - 200GB of hard drive space to each of those, they should stand up and stay running. Obviously, all of this comes with the caveat that you'd be running below standard specs, so you run the risk of capture not starting or staying up, or the ESA falling over. But you should get enough out of this setup to at least check out v11.
If you want to get creative, it is possible to put both Decoder services on the same host, but NetWitness won't let you ingest from two services on the same host natively. You have to go to Decoder --> Explore --> sys --> config --> service.name.override and enter different names for your Log Decoder and Packet Decoder services. Those two services should be able to run on the same VM, which brings your total down to 20 cores, 80GB of RAM. and 1TB of space to the whole setup.