Packages
Before installation, take a moment to understand the Trisul packages. Each package handles a different part of the system, and this page gives you a clear idea of what each package does so you know exactly what you are installing.
The Trisul Network Analytics system consists of 3 Core and 2 Optional Plugin packages.
Core Packagesβ
All three core packages are required for a complete setup, while plugin packages are optional.
- π« trisul-probe
- Handles network capture and stream processing. This is the component that observes your network traffic and extracts analytics data from it.
- π« trisul-hub
- Stores, indexes, and lets you query the data coming from probes. This is where all captured information is kept and searched.
- π« webtrisul
- Provides the web interface you log into. This is the dashboard where you view charts, reports, and analytics.
Plugin Packagesβ
These are optional and extend Trisulβs capabilities:
- π trisul-badfellas
- BadFellas plugin adds threat-intelligence checks by comparing your traffic against known malicious IPs and domains.
- π trisul-geo
- Geo plugin adds geolocation data, showing the country, ASN, and city information for the IPs seen in your traffic.
Meta Packageβ
A meta-package called trisul-full is also available (on RHEL-based systems, it's the yum group Trisul Full). This is a shortcut package that installs all of the above (core + plugins) in one step.
Now that you know what each package does, follow the install steps for your platform in Installing.