Learn how to install Cortex XSOAR On-prem, including system requirements and adding a license.
Cortex XSOAR is delivered as a self-contained virtual appliance. It includes a built-in, distributed data store that handles all database, caching, and data warehousing functions.
Note
As the data store is an integral part of Cortex XSOAR, you don't need to connect to an external Elasticsearch cluster. You do not need to procure, license, or manage a separate Elasticsearch instance. The necessary components are included within your Cortex XSOAR license.
Before installing Cortex XSOAR, ensure your environment meets all requirements, avoiding installation issues and enabling a smooth setup. Depending on your needs, decide whether to deploy a standalone node or a cluster of three nodes for optimal performance.
Deployment mode | Overview |
|---|---|
Standalone | Standalone uses a single node, which is more suitable for small-scale data scenarios. A node is a virtual machine (VM) with a distinct host IP address that runs the Cortex XSOAR application. Deployment on a standalone environment involves setting up one VM. After deploying the relevant image file, a textual UI guides you through the installation process, which includes installing the cluster from one node and setting the node's IP address. NoteCurrently, if you deploy a single node (standalone), you can't switch to a cluster of three nodes. |
Cluster | A cluster is a group of three nodes that are managed together and participate in workload management. It is suitable for large-scale data production environments and High Availability and load balancing. For more information about High Availability, see High Availability for Cortex XSOAR. For more information about load balancing, see Load balancing for Cortex XSOAR. Deployment on a cluster involves:
|
Note
Each node must meet the minimum specifications, depending on whether you require extra small, small, medium, or large scale. For more information, see System Requirements.
Supported deployment platforms
Cortex XSOAR supports the following image files, which are downloaded from Cortex Gateway:
Image file | Platform |
|---|---|
OVA | Deploy on the following platforms:
|
VHD | Deploy on Microsoft Hyper-V. For more information, see Install Cortex XSOAR on a VM deployed on Hyper-V. |
Post-installation
After installation, add your license to Cortex XSOAR and set up a secure HTTP connection, if required.
You can optimize system performance, such as adding or removing nodes in a cluster. For more information, see Post-installation and Optimize performance and robustness from the textual UI.