Skip to content

Latest commit

 

History

History

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

README.md

AWS Sensor Single

Single-instance Corelight sensor on AWS EC2.

Usage

module "sensor" {
  source = "github.com/corelight/terraform//modules/aws/sensor-single?ref=v28.4.0-1"

  ami_id            = "ami-12345abc"
  aws_key_pair_name = "your-key-pair"
  community_string  = "your-community-string"

  monitoring_interface_subnet_id   = "subnet-123abc"
  monitoring_security_group_vpc_id = "vpc-456def"

  management_interface_subnet_id   = "subnet-789ghi"
  management_security_group_vpc_id = "vpc-456def"

  license_key_file_path = "/path/to/license.txt"
}

Requirements

Name Version
terraform >=1.3.2
aws >= 5

Providers

Name Version
aws >= 5

Inputs

Name Description Type Default Required
ami_id The AMI ID provided by Corelight string n/a yes
aws_key_pair_name The name of the AWS key pair that will be used to access the sensor instances in the auto-scale group string n/a yes
community_string The community string (api password) for sensor management string n/a yes
custom_sensor_user_data Custom user data for a sensor if the default doesn't apply string "" no
deployment_name Name prefix for all resources (used to avoid naming conflicts) string "corelight-sensor" no
ebs_volume_size The size, in GB, of the EBS volume to be attached to the instance. Not recommended to set lower than 500GB number 500 no
egress_allow_cidrs The IP range allowed outbound for both network interfaces. Typically can be left as default list(string)
[
"0.0.0.0/0"
]
no
fleet_http_proxy (optional) the proxy URL for HTTP traffic from the fleet string "" no
fleet_https_proxy (optional) the proxy URL for HTTPS traffic from the fleet string "" no
fleet_no_proxy (optional) hosts or domains to bypass the proxy for fleet traffic string "" no
fleet_server_sslname (optional) the SSL hostname for the fleet server string "1.broala.fleet.product.corelight.io" no
fleet_token (optional) the pairing token from the Fleet UI. Must be set if 'fleet_url' is provided string "" no
fleet_url (optional) the URL of the fleet instance from the Fleet UI. Must be set if 'fleet_token' is provided string "" no
health_check_allow_cidrs IP range to allow health checks. Typically the CIDR of the VPC being monitored list(string)
[
"0.0.0.0/0"
]
no
iam_instance_profile_name Name of the IAM instance profile that should be attached to the EC2 instance string "" no
instance_name The name for the sensor EC2 instance (defaults to <deployment_name>-sensor) string null no
instance_type The type of the EC2 instance string "c5.2xlarge" no
license_key_file_path The path to your Corelight sensor license key. This must be provided if not licensing through fleet string "" no
management_interface_id Used in place of the 'management_interface' variable if you would like to provide one string "" no
management_interface_name The name of the management interface for the sensor (defaults to <deployment_name>-mgmt-nic) string null no
management_interface_public_ip The flag to determine if the management interface for the sensor should have a publicly assigned IP address bool false no
management_interface_subnet_id The subnet id of the management interface for the sensor string "" no
management_security_group_description Description of the management ENI security group string "Corelight Sensor Managment SG" no
management_security_group_id Used in place of the 'management_security_group' variable if you would like to provide one string "" no
management_security_group_name Name of the security group the module will provision for the management ENI (defaults to <deployment_name>-mgmt-sg) string null no
management_security_group_vpc_id Security group VPC ID module will use to provision the management ENI security group string "" no
mirror_ingress_allow_cidrs IP range to allow EC2 mirroring. Typically the CIDR of the VPC being monitored list(string)
[
"0.0.0.0/0"
]
no
monitoring_interface_id The ID of a pre-exiting ENI if you would rather create it outside of the module string "" no
monitoring_interface_name The name of the monitoring interface for the sensor (defaults to <deployment_name>-mon-nic) string null no
monitoring_interface_subnet_id Subnet where the monitoring ENI should reside string "" no
monitoring_security_group_description Description of the monitoring ENI security group string "Corelight Sensor Monitoring SG" no
monitoring_security_group_id Used in place of the 'monitoring_security_group' variable if you would like to provide one string "" no
monitoring_security_group_name Name of the security group the module will provision for the monitoring ENI (defaults to <deployment_name>-mon-sg) string null no
monitoring_security_group_vpc_id Security group VPC ID module will use to provision the monitoring ENI security group string "" no
ssh_allow_cidrs List of IPs (/32) to grant access to port 22 list(string) [] no

Outputs

Name Description
management_interface_id Network interface ID for management traffic
monitoring_interface_id Network interface ID for monitoring traffic
sensor_instance_id EC2 instance ID of the sensor

For deployment guidance, sizing recommendations, troubleshooting, and architecture details, see the official Corelight documentation.