Overview
ThreatDefence provides two types of appliances to collect and forward data to the SecOps platform: the Network Sensor for network detection and response (NDR), and the Syslog Forwarder for log collection from your existing infrastructure. Both are available as virtual appliances, with the Network Sensor also offered as a physical hardware option for larger environments.
Network Sensor (NDR)
The ThreatDefence Network Sensor provides passive monitoring of network traffic for visibility, intrusion detection, and behavioural analytics. It is available as a physical appliance for enterprise and data-centre environments, or as a virtual appliance for smaller or cloud-only deployments.
Overview — Deployment architecture, SPAN/port mirroring setup, and connectivity requirements
Physical Sensor — Hardware specifications and installation
Virtual Sensor — Virtual appliance setup and configuration
Syslog Forwarder
The ThreatDefence Syslog Forwarder (TD-SYSLOG-VM) is a lightweight Linux virtual appliance that collects logs from your environment and forwards them securely over an encrypted TLS channel to the ThreatDefence platform. It runs on any common hypervisor or cloud provider, including VMware, Hyper-V, and AWS.
Overview — Architecture, VM resource requirements, and supported platforms
Deployment — Step-by-step deployment guide
Onboarding Syslog Data — Configuring your devices to send logs
Last updated

