Kaspersky Next XDR Expert

Deployment of Kaspersky Next XDR Expert

Expand all | Collapse all

Following this scenario, you can prepare your infrastructure for the deployment of Open Single Management Platform and all the required components for Kaspersky Next XDR Expert, prepare the configuration file containing the installation parameters, and deploy the solution by using the Kaspersky Deployment Toolkit utility (hereinafter referred to as KDT).

Before you deploy Open Single Management Platform and Kaspersky Next XDR Expert components, we recommend reading the Hardening Guide.

The deployment scenario proceeds in stages:

  1. Selecting the option for deploying Kaspersky Next XDR Expert

    Select the configuration of Kaspersky Next XDR Expert that best suits your organization. You can use the sizing guide that describes the hardware requirements and the recommended deployment option in relation to the number of devices in the organization.

    Depending on the deployment option you choose, you may need the following hosts for the function of Kaspersky Next XDR Expert:

    • Administrator host
    • Target hosts
    • DBMS host (only for the distributed deployment)
    • KATA/KEDR host (optional)

    The distributed and single node deployment schemes are available:

    • Distributed deployment

      The recommended option for deploying Kaspersky Next XDR Expert. In the distributed deployment, the Kaspersky Next XDR Expert components are installed on several worker nodes of the Kubernetes cluster and if one node fails, the cluster can restore the operation of components on another node.

      In this configuration, you need at least seven hosts:

      • 1 administrator host
      • 4 target hosts for installing the Kubernetes cluster and the Kaspersky Next XDR Expert components
      • 1 host for installing the DBMS
      • 1 KUMA target host for installing the KUMA services

      In this configuration, the DBMS can be installed on a host that is located outside or inside the Kubernetes cluster.

    • Single node deployment

      In the single node deployment, all Kaspersky Next XDR Expert components are installed on a single node of the Kubernetes cluster. You can perform the single node deployment of Kaspersky Next XDR Expert if you need a solution that requires fewer computing resources (for example, for demonstration purposes).

      In this configuration, you need at least three hosts:

      • 1 administrator host
      • 1 target host for installing the Kubernetes cluster, the Kaspersky Next XDR Expert components, and the DBMS
      • 1 KUMA target host for installing the KUMA services

      In this configuration, the DBMS does not require a separate node but should be installed manually on the primary node before the Kaspersky Next XDR Expert deployment. The DBMS host can be included in the cluster only for evaluation and demonstration purposes.

  2. Downloading the distribution package with the Kaspersky Next XDR Expert components

    The distribution package contains the following components:

    • Transport archive with the Kaspersky Next XDR Expert components and End User License Agreements for Kaspersky Next XDR Expert and KDT
    • Archive with the KDT utility, and templates of the configuration file and KUMA inventory file
  3. Installing a database management system (DBMS)

    Manually install the DBMS on the separated server outside the Kubernetes cluster, if needed.

    Skip this step if you want to install the DBMS inside the cluster. KDT will install the DBMS during the Kaspersky Next XDR Expert deployment. In this case, the Kaspersky Next XDR Expert components and the DBMS will use one target host.

  4. Preparing the administrator and target hosts

    Based on the selected deployment scheme, define the number of target hosts on which you will deploy the Kubernetes cluster and the Kaspersky Next XDR Expert components included in this cluster. Prepare the selected administrator and target hosts for deployment of Kaspersky Next XDR Expert.

    How-to instructions:

  5. Preparing the KUMA hosts

    Prepare the KUMA target hosts for the installation of the KUMA services (collectors, correlators, and storages).

    How-to instruction: Preparing the hosts for installation of the KUMA services

  6. Preparing the KUMA inventory file for installation of the KUMA services

    Prepare the KUMA inventory file in the YAML format. The KUMA inventory file contains parameters for installation of the KUMA services.

    How-to instruction: Preparing the KUMA inventory file

  7. Preparing the configuration file

    Prepare the configuration file in the YAML format. The configuration file contains the list of target hosts for deployment and a set of installation parameters of the Kaspersky Next XDR Expert components.

    If you deploy Kaspersky Next XDR Expert on a single node, use the configuration file that contains the installation parameters specific for the single node deployment.

    How-to instructions:

    You can fill out the configuration file template manually; or use the Configuration wizard to specify the installation parameters that are required for the Kaspersky Next XDR Expert deployment, and then generate the configuration file.

    How-to instruction: Specifying the installation parameters by using the Configuration wizard

  8. Deployment of Kaspersky Next XDR Expert

    Deploy Kaspersky Next XDR Expert by using KDT. KDT automatically deploys the Kubernetes cluster within which the Kaspersky Next XDR Expert components and other infrastructure components are installed.

    How-to instruction: Installing Kaspersky Next XDR Expert

  9. Installing the KUMA services

    Install the KUMA services (collectors, correlators, and storages) on the prepared KUMA target hosts that are located outside the Kubernetes cluster.

    How-to instruction: Installing KUMA services

  10. Configuring integration with Kaspersky Anti Targeted Attack Platform

    Install Central Node to receive telemetry from Kaspersky Anti Targeted Attack Platform, and then configure integration between Kaspersky Next XDR Expert and KATA/KEDR to manage threat response actions on assets connected to Kaspersky Endpoint Detection and Response servers.

    If necessary, you can install multiple Central Node components to use them independently of each other or to combine them for centralized management in the distributed solution mode. To combine multiple Central Node components, you have to organize the servers with the components into a hierarchy.

    When configuring the Central Node servers, you have to specify the minimum possible value in the Storage field, to avoid duplication of data between the Kaspersky Next XDR Expert and KEDR databases.

In this section

Hardening Guide

Deployment scheme: Distributed deployment

Deployment scheme: Single node deployment

Ports used by Kaspersky Next XDR Expert

Preparation work and deployment

Kaspersky Next XDR Expert maintenance