The EDR Telemetry Store virtual appliance is delivered as an Open Virtual Appliance (OVA) package that must be installed on your hypervisor. The appliance is based on AlmaLinux 9.6 and uses OpenSearch technology to ingest, store, and search the telemetry data. For more information, see About OpenSearch.
Depending on the size of your environment, you require multiple EDR Telemetry Store virtual appliances configured with different roles and sizes.
To install and deploy the appliance:
Follow the instructions for your specific hypervisor to add and install the EDR Telemetry Store OVA package.
After the installation is complete, power on the virtual appliance.
Perform the initial appliance configuration and deploy the EDR Telemetry Store cluster.
For more information about allocating more storage to the telemetry databases, see Plan your EDRF On-prem deployment.