2.2 Hardware Requirements

The Sentinel Rapid Deployment server components run on x86-64 (64-bit) hardware, with some exceptions based on operating system, as described in the Section 2.1.1, Supported Operating Systems. Sentinel is certified on AMD Opteron and Intel Xeon hardware. Itanium servers are not supported.

This section includes some general hardware recommendations for Sentinel system design. Design recommendations are based on event rate ranges. However, these recommendations are based on the following assumptions:

The hardware recommendations for a Sentinel implementation can vary based on the individual implementation, so it is recommended that Novell Consulting Services or any of Novell Sentinel partners be consulted prior to finalizing the Sentinel architecture. The recommendations below can be used as a guideline.

In SLES version, the database is embedded with the Sentinel Rapid Deployment server and is installed on the same machine along with the server.

NOTE:Because of high event loads and local caching, the Sentinel Server is required to have a local or shared striped disk array (RAID) with a minimum of 4 disk spindles.

Table 2-2 Single Machine Configuration (up to 2000 eps)

Components

RAM

Space

CPU

Machine 1: Sentinel Rapid Deployment Server

  • Embedded PostgreSQL database (3 GB)

  • Collector Manager (1228 MB)

  • DAS_Core (1579 MB)

  • DAS_Binary (1404 MB)

  • Correlation Engine (1073 MB)

  • 4 Collectors (Generic, Cisco, Snort, and IBM generating 500 eps each)

  • 10 Correlation Rules Deployed

  • 10 unique Active Views

  • 3 simultaneous users

  • 2 Maps Deployed

16 GB

1 TB, SAS (15K rpm) Hard Disk(s)

Hardware RAID 10

Dell PowerEdge 2900,2 x Quad-Core Intel Xeon E5310 (1.6 GHz) with Gigabit Ethernet NIC

Table 2-3 Three Machine Configuration (up to 5000 eps)

Components

RAM

Space

CPU

Machine 1: Sentinel Rapid Deployment Server

  • Embedded PostgreSQL database (3 GB)

  • Collector Manager (1228 MB)

  • DAS_Core (1579 MB)

  • DAS_Binary (1404 MB)

  • Correlation Engine (1073 MB)

  • 4 Collectors (generating 500 eps each, 1500 EPS from remote Collector Manager 1,and 1500 EPS from remote Collector Manager 2.

16 GB

1 TB, SAS (15K rpm) Hard Disk(s)

Hardware RAID 10

Dell PowerEdge 2900,2 x Quad-Core Intel Xeon E5310 (1.6 GHz) with Gigabit Ethernet NIC

Machine 2: Collector Manager

  • Collector Manager/Collectors

  • 3 Collectors (generating 500 eps each)

4 GB

300 GB,SATA (3 Gbit/s) Hard Disk

Intel Core 2 Duo E6750 (2.66 GHz) with Gigabit Ethernet NIC

Machine 3: Collector Manager

  • Collector Manager/Collectors

  • 3 Collectors (generating 500 eps each)

4 GB

300 GB,SATA (3 Gbit/s) Hard Disk

Intel Core 2 Duo E6750 (2.66 GHz) with Gigabit Ethernet NIC