Kaspersky Next XDR Expert

Deployment of Kaspersky Next XDR Expert

Expand all | Collapse all

Following this scenario, you can prepare your infrastructure for the deployment of Open Single Management Platform and all the required components for Kaspersky Next XDR Expert, prepare the configuration file containing the installation parameters, and deploy the solution by using the Kaspersky Deployment Toolkit utility (hereinafter referred to as KDT).

Before you deploy Open Single Management Platform and Kaspersky Next XDR Expert components, we recommend reading the Hardening Guide.

The deployment scenario proceeds in stages:

  1. Selecting the option for deploying Kaspersky Next XDR Expert

    Select the configuration of Kaspersky Next XDR Expert that best suits your organization. The multi-node and single-node deployment are available.

  2. Downloading the distribution package with the Kaspersky Next XDR Expert components

    The distribution package contains the following components:

    • Transport archive with the Kaspersky Next XDR Expert components and End User License Agreements for Kaspersky Next XDR Expert and KDT
    • Archive with the KDT utility, and templates of the configuration file and KUMA inventory file
  3. Installing a database management system (DBMS)

    For the multi-node deployment, manually install the DBMS on the separated server outside the Kubernetes cluster.

    For the single-node deployment, manually install the DBMS on the target host before the Kaspersky Next XDR Expert deployment. In this case, the DBMS and Kaspersky Next XDR Expert components are installed on the same target host, but the DBMS is not included in the Kubernetes cluster.

  4. Preparing the administrator and target hosts

    Based on the selected deployment scheme, define the number of target hosts on which you will deploy the Kubernetes cluster and the Kaspersky Next XDR Expert components included in this cluster. Prepare the selected administrator and target hosts for deployment of Kaspersky Next XDR Expert.

    How-to instructions:

  5. Preparing the KUMA hosts

    Prepare the KUMA target hosts for the installation of the KUMA services (collectors, correlators, and storages).

    How-to instruction: Preparing the hosts for installation of the KUMA services

  6. Preparing the KUMA inventory file for installation of the KUMA services

    Prepare the KUMA inventory file in the YAML format. The KUMA inventory file contains parameters for installation of the KUMA services.

    How-to instruction: Preparing the KUMA inventory file

  7. Preparing the configuration file

    Prepare the configuration file in the YAML format. The configuration file contains the list of target hosts for deployment and a set of installation parameters of the Kaspersky Next XDR Expert components.

    If you deploy Kaspersky Next XDR Expert on a single-node, use the configuration file that contains the installation parameters specific for the single-node deployment.

    How-to instructions:

    You can fill out the configuration file template manually; or use the Configuration wizard to specify the installation parameters that are required for the Kaspersky Next XDR Expert deployment, and then generate the configuration file.

    How-to instruction: Specifying the installation parameters by using the Configuration wizard

  8. Deployment of Kaspersky Next XDR Expert

    Deploy Kaspersky Next XDR Expert by using KDT. KDT automatically deploys the Kubernetes cluster within which the Kaspersky Next XDR Expert components and other infrastructure components are installed.

    How-to instruction: Installing Kaspersky Next XDR Expert

  9. Installing the KUMA services

    Install the KUMA services (collectors, correlators, and storages) on the prepared KUMA target hosts that are located outside the Kubernetes cluster.

    How-to instruction: Installing KUMA services

  10. Configuring integration with Kaspersky Anti Targeted Attack Platform

    Install Central Node to receive telemetry from Kaspersky Anti Targeted Attack Platform, and then configure integration between Kaspersky Next XDR Expert and KATA/KEDR to manage threat response actions on assets connected to Kaspersky Endpoint Detection and Response servers.

    If necessary, you can install multiple Central Node components to use them independently of each other or to combine them for centralized management in the distributed solution mode. To combine multiple Central Node components, you have to organize the servers with the components into a hierarchy.

    When configuring the Central Node servers, you have to specify the minimum possible value in the Storage field, to avoid duplication of data between the Kaspersky Next XDR Expert and KEDR databases.

In this section

Hardening Guide

Deployment schemes

Ports used by Kaspersky Next XDR Expert

Preparation work and deployment

Kaspersky Next XDR Expert maintenance

Demonstration deployment of Kaspersky Next XDR Expert