> For the complete documentation index, see [llms.txt](https://docs.vectra.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.vectra.ai/deployment/getting-started/appliance-specifications.md).

# Appliance specifications

## Appliance and Sensor Specifications

The Vectra AI Platform provides coverage, clarity, and control across the entire modern network. Coverage for attackers’ moves across all of your network, identity, and cloud threat surfaces. AI signal clarity prioritizes attacks with AI assistants to automatically triage, correlate, and prioritize threats across domains. We put you in control with context to discover, hunt, investigate, and stop attacks early in their progression - all while spending less time prioritizing alerts.

Software updates, including new threat intelligence and detection algorithms, are included with your license. They are delivered to your system on a regular basis to ensure continuous protection from the latest threats. [Match](/deployment/match/deployment/introduction-and-requirements.md) customers can also choose to enable automated curated ruleset updates that provide signature updates.

Appliances are supported in traditional physical on-prem, virtual hypervisor, and IaaS cloud environments. Vectra AI supports AWS, Azure, and GCP clouds along with VMware, Hyper-V, Nutanix, and KVM hypervisors. We continually evaluates customer demand for support of new environments. Please check with your account team for questions on future plans.

X-Series and S-Series appliances can perform “Sensor” duties, passively capturing network traffic out-of-band and forwarding a metadata stream to the “Brain” appliance for further processing. B-Series and X-Series appliances can serve as the Brain for your deployment. They run network detection models locally and serve as customer side integration point for added coverage, response, and context enhancement options. The Brain appliance is connected to the Vectra AI cloud where the Respond UX provides the UI along with advanced features such as Instant Investigation and AI-Assisted Search. In Quadrant UX deployments, the Brain appliance serves the classic UI locally. If you are unsure of your deployment type, please see [Analyst UX options (RUX vs QUX)](/deployment/getting-started/analyst-ux-options-rux-vs-qux.md).

Network traffic can be directed to appliances through physical SPAN/Copy/Mirror ports, TAPs, and packet brokers. Native cloud packet forwarding options are supported such as VPC Traffic Mirroring (AWS), VTAP (Azure), and NSI (GCP). Hypervisor based packet forwarding options are also supported. Sensors support a variety of encapsulation methods such as ERSPAN, GRE, VXLAN and GENEVE. For additional detail, please see the [Vectra NDR (Detect) and Network Identity Architecture Overview](/deployment/getting-started/ndr-network-identity-architecture.md).

## Physical Appliance Specifications

### Definitions

{% hint style="info" %}
**Performance**

Refers to the amount of network traffic observed by Sensors that a Sensor can produce metadata for, or the amount of traffic observed by Sensors that a Brain can process metadata for including optional output to [Stream](/deployment/stream/introduction-and-requirements.md).

Match performance is the expected performance when [Match](/deployment/match/deployment/introduction-and-requirements.md) is enabled on a Sensor or mixed-mode appliance.

The performance numbers are based upon average throughput a given Sensor/Brain can process. Actual performance may vary depending on traffic composition. Please contact Vectra AI to discuss further.
{% endhint %}

{% hint style="info" %}
**Alternate Interface Configuration**

When an appliance lists an alternate interface configuration as an option in any below table, that means that it supports configuration changes that allow the management interface and/or capture interfaces to be changed from their default assignment.

For the [X29](/deployment/ndr-physical-appliances/x-series/x29.md)/[M29](/deployment/ndr-physical-appliances/m-series/m29.md) ,[X47](/deployment/ndr-physical-appliances/x-series/x47.md)/[M47](/deployment/ndr-physical-appliances/m-series/m47.md), and [S1v2](/deployment/ndr-physical-appliances/s-series/s1v2.md) appliances, one of the 10 GbE SFP+ ports that are normally used for capture traffic can be configured to be used as a management interface. When configured as such, the original MGT1 copper port would be unused.

For the [S1](/deployment/ndr-physical-appliances/s-series/s1.md) appliance there are [4 different port option settings](/deployment/ndr-physical-appliances/s-series/s1.md#port-option-settings) that vary what is available for use as the management interface and the capture interfaces.

Please see the quick start guides for these appliances for full details and how to configure the alternate interface configurations.
{% endhint %}

{% hint style="info" %}
**Paired Sensors**

Refers to how many Sensors (physical, virtual, or cloud) an appliance can pair with.
{% endhint %}

{% hint style="info" %}
**Tracked Hosts**

Refers to how many hosts the appliance running in Brain or Mixed mode can track simultaneously (open IP (host) sessions). Brains can typically retain and display data for larger numbers of hosts, this only refers to how many hosts the system can process metadata for simultaneously.
{% endhint %}

### Supported SFPs and QSFPs

For any appliance that supports SFP interface (SFP+, SFP28, QSFP, QSFP28, etc), please see the [supported SFPs and QSFPs](/deployment/ndr-physical-appliances/supported-sfps-and-qsfps.md) article for additional details about specific SFPs supported per physical appliance..

Please see the [quick start guides](/deployment/ndr-physical-appliances.md) for your physical appliance to see port diagrams showing the interfaces available. Some appliances offer options to configure a capture port SFP for use as the management port. Your appliance may support several, only one, or no SFPs.

{% hint style="info" %}
**Please Note (SFPs available at no cost or for an added cost):**

These purchasing guidelines apply to SFPs ordered as part of your appliance order:

* Up to 2 (if supported by your appliance model) SFP, SFP+, or SFP28 modules can be included at no additional cost in your Vectra appliance order.
  * This is valid for each appliance in your order.
* Additional SFP(s) of any type over the two specified above will incur additional cost.
* All 40/100G QSFPs will incur additional cost over the base price of the appliance.
  {% endhint %}

### X-Series Appliances

X-Series appliances can operate in Sensor, Brain, or Mixed mode deployments. For more details about appliance modes, please see [Physical appliance modes and switching between them](/deployment/ndr-physical-appliances/physical-appliance-modes-and-switching-between-them.md).

#### Interfaces and Capacity

| Specification                            | X3                                         | X29                                        | X47                                            |
| ---------------------------------------- | ------------------------------------------ | ------------------------------------------ | ---------------------------------------------- |
| Management Interfaces (MGT)              | 2 x 1GbE Copper                            | 2 x 1 GbE Copper                           | 2 x 1 GbE Copper                               |
| Capture Interfaces                       | <p>2 x 1 GbE Copper<br>2 x 10 GbE SFP+</p> | <p>2 x 1 GbE Copper<br>2 x 10 GbE SFP+</p> | <p>2 x 1 GbE Copper<br>2 x 10/25 GbE SFP28</p> |
| Alternate Interface Configuration        | N/A                                        | Yes[^1]                                    | Yes[^1]                                        |
| [Paired Sensors](#user-content-fn-2)[^2] | 150                                        | 150                                        | 150                                            |
| [Tracked Hosts](#user-content-fn-3)[^3]  | 100,000                                    | 150,000                                    | 150,000                                        |

#### Performance

<table><thead><tr><th width="259.0859375">Specification</th><th>X3</th><th>X29</th><th>X47</th></tr></thead><tbody><tr><td>Sensor Mode Performance</td><td>9 Gbps</td><td>15 Gbps</td><td>20 Gbps</td></tr><tr><td>Mixed Mode Performance</td><td>8 Gbps</td><td>8 Gbps</td><td>15 Gbps</td></tr><tr><td>Brain Mode Performance</td><td>14 Gbps</td><td>20 Gbps</td><td>30 Gbps</td></tr><tr><td>Match Performance — Sensor</td><td>3 Gbps</td><td>9 Gbps</td><td>13 Gbps</td></tr><tr><td>Match Performance — Mixed</td><td>1 Gbps</td><td>4.6 Gbps</td><td>6 Gbps</td></tr></tbody></table>

#### Power and Electrical

<table><thead><tr><th width="175.109375">Specification</th><th>X3</th><th>X29</th><th>X47</th></tr></thead><tbody><tr><td>Input Voltage</td><td>Dual power supplies, auto sensing 100-240 VAC, 50-60 Hz</td><td>Dual power supplies, auto sensing 100-240 VAC, 50-60 Hz</td><td>Dual power supplies, auto sensing 100-240 VAC, 50-60 Hz</td></tr><tr><td>Power — Normal</td><td>277 W (945 BTU/h)</td><td>296 W (1010 BTU/h)</td><td>602 W (2204 BTU/h)</td></tr><tr><td>Power — Max</td><td>392 W (1338 BTU/h)</td><td>337 W (1150 BTU/h)</td><td>866 W (2966 BTU/h)</td></tr><tr><td>Current — 110 VAC</td><td>3.5 A at 110 VAC</td><td>2.9 A at 110 VAC</td><td>8.0 A at 110 VAC</td></tr><tr><td>Current — 220 VAC</td><td>1.7 A at 220 VAC</td><td>1.5 A at 220 VAC</td><td>3.9 A at 220 VAC</td></tr></tbody></table>

#### Physical, Environment, and Reliability

<table><thead><tr><th width="231.22265625">Specification</th><th>X3</th><th>X29</th><th>X47</th></tr></thead><tbody><tr><td>Dimensions</td><td>42.8 mm (1.685 inches) H<br>482 mm (18.976 inches) W<br>662.19 mm (26.070 inches) D</td><td>42.8 mm (1.685 inches) H<br>482 mm (18.976 inches) W<br>787.04 mm (30.99 inches) D</td><td>42.8 mm (1.685 inches) H<br>482 mm (18.976 inches) W<br>787.04 mm (30.99 inches) D</td></tr><tr><td>Weight</td><td>16.6 kg (36.6 lb)</td><td>17.5 kg (38.6 lb)</td><td>20.3 kb (44.8 lb)</td></tr><tr><td>Operating temperature</td><td>10° to 35° C (50° to 95° F)</td><td>10° to 35° C (50° to 95° F)</td><td>10° to 35° C (50° to 95° F)</td></tr><tr><td>Non-operating temperature</td><td>-40° to 65° C (-40° to 149° F)</td><td>-40° to 65° C (-40° to 149° F)</td><td>-40° to 65° C (-40° to 149° F)</td></tr><tr><td>Airflow</td><td>Front to back, 12.3 l/s (26 CFM)</td><td>Front to back, 16.9 l/s (35.8 CFM)</td><td>Front to back, 52.8 l/s (111.8 CFM)</td></tr><tr><td>Sound Power</td><td>3.8 bels</td><td>7.2 bels</td><td>8.4 bels</td></tr><tr><td>MTBCF</td><td>45,700 hours</td><td>87,600 hours</td><td>97,300 hours</td></tr></tbody></table>

### M-Series Appliances

M-Series appliances share chassis with corresponding X-Series models, but are not equivalent in role. M-Series appliances are used for [Stream](/deployment/stream/introduction-and-requirements.md) deployments.

#### Interfaces and Performance

<table><thead><tr><th width="271.59375">Specification</th><th>M29</th><th>M47</th></tr></thead><tbody><tr><td>Management Interfaces (MGT)</td><td>2 x 1 GbE Copper</td><td>2 x 1 GbE Copper</td></tr><tr><td>Capture <a data-footnote-ref href="#user-content-fn-4">Interfaces</a></td><td>2 x 1 GbE Copper<br>2 x 10 GbE SFP+</td><td>2 x 1 GbE Copper<br>2 x 10/25 GbE SFP28</td></tr><tr><td>Alternate Interface Configuration</td><td><a data-footnote-ref href="#user-content-fn-1">Yes</a></td><td><a data-footnote-ref href="#user-content-fn-1">Yes</a></td></tr><tr><td>Stream Performance</td><td>75 Gbps</td><td>75 Gbps</td></tr></tbody></table>

#### Power and Electrical

<table><thead><tr><th width="172.40234375">Specification</th><th>M29</th><th>M47</th></tr></thead><tbody><tr><td>Input Voltage</td><td>Dual power supplies, auto sensing 100-240 VAC, 50-60 Hz</td><td>Dual power supplies, auto sensing 100-240 VAC, 50-60 Hz</td></tr><tr><td>Power — Normal</td><td>296 W (10010 BTU/h)</td><td>602 W (2204 BTU/h)</td></tr><tr><td>Power — Max</td><td>337 W (1150 BTU/h)</td><td>866 W (2966 BTU/h)</td></tr><tr><td>Current — 110 VAC</td><td>2.9 A at 110 VAC</td><td>8.0 A at 110 VAC</td></tr><tr><td>Current — 220 VAC</td><td>1.5 A at 220 VAC</td><td>3.9 A at 220 VAC</td></tr></tbody></table>

#### Physical, Environment, and Reliability

<table><thead><tr><th width="230.796875">Specification</th><th>M29</th><th>M47</th></tr></thead><tbody><tr><td>Dimensions</td><td>42.8 mm (1.685 inches) H<br>482 mm (18.976 inches) W<br>787.04 mm (30.99 inches) D</td><td>42.8 mm (1.685 inches) H<br>482 mm (18.976 inches) W<br>787.04 mm (30.99 inches) D</td></tr><tr><td>Weight</td><td>17.5 kg (38.6 lb)</td><td>20.3 kb (44.8 lb)</td></tr><tr><td>Operating temperature</td><td>10° to 35° C (50° to 95° F)</td><td>10° to 35° C (50° to 95° F)</td></tr><tr><td>Non-operating temperature</td><td>-40° to 65° C (-40° to 149° F)</td><td>-40° to 65° C (-40° to 149° F)</td></tr><tr><td>Airflow</td><td>Front to back, 16.9 l/s (35.8 CFM)</td><td>Front to back, 52.8 l/s (111.8 CFM)</td></tr><tr><td>Sound Power</td><td>7.2 bels</td><td>8.4 bels</td></tr><tr><td>MTBCF</td><td>87,600 hours</td><td>97,300 hours</td></tr></tbody></table>

### S-Series Appliances

S-Series appliances operate in Sensor mode only. For more details about appliance modes, please see [Physical appliance modes and switching between them](https://docs.vectra.ai/~/changes/335/deployment/ndr-physical-appliances/physical-appliance-modes-and-switching-between-them).

#### Interfaces and Capacity

| Specification                     | S1                                         | S1v2                                       | S11                         | S17                                         | S101                                                                                     | S127                                                            |
| --------------------------------- | ------------------------------------------ | ------------------------------------------ | --------------------------- | ------------------------------------------- | ---------------------------------------------------------------------------------------- | --------------------------------------------------------------- |
| Management Interfaces (MGT)       | 2 x 1 GbE Copper                           | 2 x 1 GbE Copper                           | 2 x 1 GbE Copper            | <p>1 x 10 GbE Copper<br>1x 1 GbE Copper</p> | 2 x 10 GbE SFP+                                                                          | 2 x 10/25 GbE SFP28                                             |
| Capture Interfaces                | <p>4 x 1 GbE Copper<br>2 x 10 GbE SFP+</p> | <p>2 x 1 GBE Copper<br>2 x 10 GbE SFP+</p> | <p>2 x 1 GbE Copper<br></p> | 1 x 10 GbE Copper                           | <p>2x 10 GbE SFP+<br>2 configurable to: 10/25 GbE SFP28, 40 GbE QSFP, 100 GbE QSFP28</p> | 2 configurable to: 10/25 GbE SFP28, 40 GbE QSFP, 100 GbE QSFP28 |
| Alternate Interface Configuration | Yes[^5]                                    | Yes[^6]                                    | N/A                         | N/A                                         | N/A                                                                                      | N/A                                                             |

#### Performance

| Specification             | S1       | S1v2     | S11      | S17      | S101    | S127    |
| ------------------------- | -------- | -------- | -------- | -------- | ------- | ------- |
| Sensor Mode Performance   | 1 Gbps   | 1 Gbps   | 2 Gbps   | 9 Gbps   | 50 Gbps | 58 Gbps |
| Match Enabled Performance | 600 Mbps | 400 Mbps | 1.2 Gbps | 2.5 Gbps | 33 Gbps | 30 Gbps |

#### Power and Electrical

| Specification     | S1                                                              | S1v2                                                                | S11                                                    | S17                                                    | S101                                                    | S127                                                    |
| ----------------- | --------------------------------------------------------------- | ------------------------------------------------------------------- | ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------- | ------------------------------------------------------- |
| Input Voltage     | Single external power supply, auto-sensing 100-240VAC, 50-60 Hz | Single[^7] external power supply, auto-sensing 100-240VAC, 50-60 Hz | Single power supply, auto-sensing 100-240VAC, 50-60 Hz | Single power supply, auto-sensing 100-240VAC, 50-60 Hz | Dual power supplies, auto sensing 100-240 VAC, 50-60 Hz | Dual power supplies, auto sensing 100-240 VAC, 50-60 Hz |
| Power — Normal    | Not available                                                   | Not available                                                       | 152 W (519 BTU/h)                                      | Not available                                          | 615 W (2098 BTU/h)                                      | 769 W (2624 BTU/h)                                      |
| Power — Max       | 45W (154 BTU/h)                                                 | 150W (512 BTU/h)                                                    | 186 W (635 BTU/h)                                      | 196 W (669 BTU/h)                                      | 868 W (2962 BTU/h)                                      | 1073 W (3661 BTU/h)                                     |
| Current — 110 VAC | 2.0 A at 100 VAC                                                | 2.0 A at 110 VAC                                                    | 1.7 A at 110 VAC                                       | 1.8 A at 110 VAC                                       | 7.9 A at 110 VAC                                        | 9.8 amps at 110 VAC                                     |
| Current — 220 VAC | 1.0 A at 240 VAC                                                | 1.0 A at 220 VAC                                                    | 0.8 A at 220 VAC                                       | 0.9 A at 220 VAC                                       | 3.8 A at 220 VAC                                        | 4.8 amps at 220 VAC                                     |

#### Physical, Environment, and Reliability

| Specification             | S1                                                                                                                | S1v2                                                                     | S11                                                                                 | S17                                                                     | S101                                                                                    | S127                                                                                      |
| ------------------------- | ----------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------ | ----------------------------------------------------------------------------------- | ----------------------------------------------------------------------- | --------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- |
| Dimensions                | <p>52 mm (2.04 in) H<br>208 mm (8.18 in) W<br>200 mm (7.87 in) D</p>                                              | <p>43.7 mm (1.7 in) H<br>339.6 mm (13.3 in) W<br>241.1 mm (9.5 in) D</p> | <p>42.8 mm (1.685 inches) H<br>434 mm (17.1 inches) W<br>535 mm (22.6 inches) D</p> | <p>42.8 mm (1.685 in) H<br>434 mm (17.1 in) W<br>461 mm (18.2 in) D</p> | <p>42.8 mm (1.685 inches) H<br>482 mm (18.976 inches) W<br>808.5 mm (31.8 inches) D</p> | <p>42.8 mm (1.685 inches) H<br>482 mm (18.976 inches) W<br>787.04 mm (30.99 inches) D</p> |
| Weight                    | <p>Without power supply unit (PSU): 1.4 kg (3.1 lb)<br>Including power supply and packaging: 4.9 kg (10.8 lb)</p> | 4.5 kb (9.9 lb)                                                          | 12.2 kg (26.9 lb)                                                                   | 9.6 kg (21.2 lb)                                                        | 21 kg (46.3 lb)                                                                         | 20.3 kg (44.8 lb)                                                                         |
| Operating temperature     | 0° to 40° C (32° to 104° F)                                                                                       | 0° to 40° C (32° to 104° F)                                              | 0° to 40° C (32° to 104° F)                                                         | 5° to 40° C (41° to 104° F)                                             | 10° to 35° C (50° to 95° F)                                                             | 10° to 35° C (50° to 95° F)                                                               |
| Non-operating temperature | -40° to 70° C (-40° to 158° F)                                                                                    | -40° to 70° C (-40° to 158° F)                                           | -40° to 70° C (-40° to 158° F)                                                      | -40° to 65° C (-40° to 149° F)                                          | -40° to 65° C (-40° to 149° F)                                                          | -40° to 65° C (-40° to 149° F)                                                            |
| Airflow                   | In bottom, out sides and back, 4.7 l/s (10 CFM)                                                                   | In front/sides, out back, CFM not available                              | Front to back, 5.4 l/s (11.4 CFM)                                                   | Front to back, 11.0 l/s (23.4 CFM)                                      | Front to back, 29.1 l/s (61.6 CFM)                                                      | Front to back, 52.8 l/s (111.8 CFM)                                                       |
| Sound Power               | 4.8 bels                                                                                                          | Not available                                                            | 5.7 bels                                                                            | 7.6 bels                                                                | 7.6 bels                                                                                | 8.4 bels                                                                                  |
| MTBCF                     | 445,000 hours                                                                                                     | 117,700 (MTBF)                                                           | 109,000 hours                                                                       | TBD                                                                     | 107,000 hours                                                                           | 102,000 hours                                                                             |

### B-Series Appliances

B-Series appliances serve as Brain appliances only. For more details about appliance modes, please see [Physical appliance modes and switching between them](https://docs.vectra.ai/~/changes/335/deployment/ndr-physical-appliances/physical-appliance-modes-and-switching-between-them).

#### Interfaces and Capacity

<table><thead><tr><th width="272.8359375">Specification</th><th>B101</th><th>B127</th></tr></thead><tbody><tr><td>Management Interfaces (MGT)</td><td>2 x 10 GbE SFP+</td><td>2 x 10/25 GbE SFP28</td></tr><tr><td>Capture Interfaces</td><td>N/A</td><td>N/A</td></tr><tr><td>Alternate Interface Configuration</td><td>N/A</td><td>N/A</td></tr><tr><td><a data-footnote-ref href="#user-content-fn-2">Paired Sensors</a></td><td>500</td><td>500</td></tr><tr><td><a data-footnote-ref href="#user-content-fn-3">Tracked Hosts</a></td><td>300,000</td><td>300,000</td></tr></tbody></table>

#### Performance

<table><thead><tr><th width="213.26953125">Specification</th><th>B101</th><th>B127</th></tr></thead><tbody><tr><td>Brain Mode Performance</td><td>75 Gbps</td><td>75 Gbps</td></tr></tbody></table>

#### Power and Electrical

<table><thead><tr><th width="176.359375">Specification</th><th>B101</th><th>B127</th></tr></thead><tbody><tr><td>Input Voltage</td><td>Dual power supplies, auto sensing 100-240 VAC, 50-60 Hz</td><td>Dual power supplies, auto sensing 100-240 VAC, 50-60 Hz</td></tr><tr><td>Power — Normal</td><td>604 W (2061 BTU/h)</td><td>773 W (2638 BTU/h)</td></tr><tr><td>Power — Max</td><td>846 W (2887 BTU/h)</td><td>1149 W (3920 BTU/h)</td></tr><tr><td>Current — 110 VAC</td><td>7.7 amps at 110 VAC</td><td>10.7 amps at 110 VAC</td></tr><tr><td>Current — 220 VAC</td><td>3.7 amps at 220 VAC</td><td>5.3 amps at 220 VAC</td></tr></tbody></table>

#### Physical, Environment, and Reliability

<table><thead><tr><th width="231.55859375">Specification</th><th>B101</th><th>B127</th></tr></thead><tbody><tr><td>Dimensions</td><td>42.8 mm (1.685 inches) H<br>482 mm (18.976 inches) W<br>808.5 mm (31.8 inches) D</td><td>42.8 mm (1.685 inches) H<br>482 mm (18.976 inches) W<br>787.04 mm (30.99 inches) D</td></tr><tr><td>Weight</td><td>21 kg (46.3 lb)</td><td>20.3 kg (44.8 lb)</td></tr><tr><td>Operating temperature</td><td>10° to 35° C (50° to 95° F)</td><td>10° to 35° C (50° to 95° F)</td></tr><tr><td>Non-operating temperature</td><td>-40° to 65° C (-40° to 149° F)</td><td>-40° to 65° C (-40° to 149° F)</td></tr><tr><td>Airflow</td><td>Front to back, 61.6 CFM = 29.1 l/s</td><td>Front to back, 111.8 CFM = 52.8 l/s</td></tr><tr><td>Sound Power</td><td>7.6 bels</td><td>8.4 bels</td></tr><tr><td>MTBCF</td><td>109,000 hours</td><td>132,000 hours</td></tr></tbody></table>

## Customer Premise Virtual (Hypervisor) Deployment

These virtual appliances are deployed in traditional hypervisor enviroments such as VMware vSphere, Hyper-V, KVM, and Nutanix.

### Virtual Brains

<table><thead><tr><th width="115.05859375">Hypervisor</th><th width="181.578125">VM Type / Version</th><th width="75.015625" align="right">Cores</th><th width="82.2734375" align="right">Memory</th><th width="118.921875">Storage (OS, Data) in GB</th><th width="118.37109375" align="right">Paired Sensors</th><th width="126.82421875" align="right">Tracked Hosts</th><th width="138.11328125">Performance</th></tr></thead><tbody><tr><td>VMware</td><td>vSphere 6.5 or later</td><td align="right">4</td><td align="right">48GB</td><td>128,512</td><td align="right">5</td><td align="right">25,000</td><td>150 Mbps</td></tr><tr><td>VMware</td><td>vSphere 6.5 or later</td><td align="right">6</td><td align="right">48GB</td><td>128,512</td><td align="right">10</td><td align="right">37,500</td><td>500 Mbps</td></tr><tr><td>VMware</td><td>vSphere 6.5 or later</td><td align="right">8</td><td align="right">64GB</td><td>128,512</td><td align="right">15</td><td align="right">50,000</td><td>2 Gbps</td></tr><tr><td>VMware</td><td>vSphere 6.5 or later</td><td align="right">16</td><td align="right">128GB</td><td>128,512</td><td align="right">25</td><td align="right">50,000</td><td>4 Gbps</td></tr><tr><td>VMware</td><td>vSphere 6.5 or later</td><td align="right">32</td><td align="right">256GB</td><td>128,512</td><td align="right">100</td><td align="right">150,000</td><td>10 Gbps</td></tr><tr><td>Nutanix</td><td>AOS 6.8.1 and higher with Prism Central (and v3 API) available</td><td align="right">32</td><td align="right">256GB</td><td>128,512</td><td align="right">100</td><td align="right">150,000</td><td>10 Gbps</td></tr></tbody></table>

### Virtual Sensors

| Hypervisor | VM Type / Version                                                 | Cores | Memory | Storage    | Performance |
| ---------- | ----------------------------------------------------------------- | ----: | -----: | ---------- | ----------- |
| VMware     | vSphere 6.5 or later                                              |     2 |   8 GB | 100 GB     | 500 Mbps    |
| VMware     | vSphere 6.5 or later                                              |     4 |   8 GB | 150 GB     | 1 Gbps      |
| VMware     | vSphere 6.5 or later                                              |     8 |  16 GB | 150 GB     | 2 Gbps      |
| VMware     | vSphere 6.5 or later                                              |    16 |  64 GB | 600 GB[^8] | 5 Gbps      |
| VMware     | vSphere 6.5 or later                                              |    32 | 114 GB | 830 GB     | 20 Gbps     |
| Hyper-V    | Windows Server 2016 w/ HW v8 or higher                            |     2 |   8 GB | 100 GB     | 500 Mbps    |
| Hyper-V    | Windows Server 2016 w/ HW v8 or higher                            |     4 |   8 GB | 150 GB     | 1 Gbps      |
| Hyper-V    | Windows Server 2016 w/ HW v8 or higher                            |     8 |  16 GB | 150 GB     | 2 Gbps      |
| Hyper-V    | Windows Server 2016 w/ HW v8 or higher                            |    16 |  64 GB | 500 GB     | 5 Gbp       |
| KVM        | Standard PC (Q35 + ICH9, 2009)                                    |     2 |   8 GB | 100 GB     | 500 Mbps    |
| KVM        | Standard PC (Q35 + ICH9, 2009)                                    |     4 |   8 GB | 150 GB     | 1 Gbps      |
| KVM        | Standard PC (Q35 + ICH9, 2009)                                    |     8 |  16 GB | 150 GB     | 2 Gbps      |
| KVM        | Standard PC (Q35 + ICH9, 2009)                                    |    16 |  64 GB | 500 GB     | 5 Gbps      |
| Nutanix    | AOS Version: 5.20.3.5 or later; AHV Version 2021105.2267 or later |     2 |   8 GB | 100 GB     | 500 Mbps    |
| Nutanix    | AOS Version: 5.20.3.5 or later; AHV Version 2021105.2267 or later |     4 |   8 GB | 150 GB     | 1 Gbps      |
| Nutanix    | AOS Version: 5.20.3.5 or later; AHV Version 2021105.2267 or later |     8 |  16 GB | 150 GB     | 2 Gbps      |
| Nutanix    | AOS Version: 5.20.3.5 or later; AHV Version 2021105.2267 or later |    16 |  64 GB | 500 GB     | 5 Gbps      |
|            |                                                                   |       |        |            |             |

## Cloud - IaaS Deployment

These virtual appliances are deployed in IaaS clouds such as AWS, Azure, and GCP.

{% hint style="info" %}
**Please Note:**

Vectra product and engineering teams monitor the changing landscape of available IaaS cloud instance types. Occassionally customers will ask if a specific new instance type is supported.

There are a number of factors that can cause Vectra AI to stay with a specific instance type versus a newer one such as:

* Cost increase vs performance increase - sometimes a newer instance, for example, might cost 17% more but only increase performance by 10%.
* Availability - not all new instance types are always available in all the locations that Vectra AI supports.

Please reach out to your account team if you have questions about specific instance types that aren't supported.
{% endhint %}

### Virtual Brains (IaaS)

<table><thead><tr><th width="83.078125">Cloud</th><th width="158.83984375">VM Type</th><th width="76.2890625" align="right">Cores</th><th width="96.7421875" align="right">Memory</th><th width="255.15625">Storage in GB (OS, Data, Data, Data)</th><th width="121.13671875" align="right">Paired Sensors</th><th width="115.79296875" align="right">Tracked Hosts</th><th width="115.84765625">Performance</th></tr></thead><tbody><tr><td>AWS</td><td>r5d.2xlarge</td><td align="right">8</td><td align="right">64 GB</td><td>256, 64, 128, 256</td><td align="right">15</td><td align="right">50,000</td><td>2 Gbps</td></tr><tr><td>AWS</td><td>r5d.4xlarge</td><td align="right">16</td><td align="right">128 GB</td><td>256, 64, 128, 256</td><td align="right">25</td><td align="right">50,000</td><td>5 Gbps</td></tr><tr><td>AWS</td><td>r5d.8xlarge</td><td align="right">32</td><td align="right">256 GB</td><td>256, 64, 128, 256</td><td align="right">100</td><td align="right">150,000</td><td>15 Gbps</td></tr><tr><td>AWS</td><td>r5.16xlarge</td><td align="right">64</td><td align="right">512 GB</td><td><a data-footnote-ref href="#user-content-fn-9">256</a>, 64, 512, 512</td><td align="right">500</td><td align="right">500,000</td><td>50 Gbps</td></tr><tr><td>Azure</td><td>Standard_E16s_v3</td><td align="right">16</td><td align="right">128 GB</td><td>256, 64, 128, 256</td><td align="right">25</td><td align="right">50,000</td><td>5 Gbps</td></tr><tr><td>Azure</td><td>Standard_E32s_v3</td><td align="right">32</td><td align="right">256 GB</td><td>256, 64, 128, 256</td><td align="right">100</td><td align="right">150,000</td><td>15 Gbps</td></tr><tr><td>GCP</td><td>n2-highmem-16</td><td align="right">16</td><td align="right">128 GB</td><td>1 TB (single partition)</td><td align="right">25</td><td align="right">50,000</td><td>5 Gbps</td></tr><tr><td>GCP</td><td>n2-highmem-32</td><td align="right">32</td><td align="right">256 GB</td><td>1 TB (single partition)</td><td align="right">100</td><td align="right">150,000</td><td>15 Gbps</td></tr><tr><td>GCP</td><td>n2-highmem-64</td><td align="right">64</td><td align="right">512 GB</td><td>1.2 TB (single partition)</td><td align="right">100</td><td align="right">150,000</td><td>50 Gbps</td></tr><tr><td>GCP</td><td>n2-highmem-96</td><td align="right">96</td><td align="right">768 GB</td><td>4 TB (single partition)</td><td align="right">100</td><td align="right">500,000</td><td>85 Gbps</td></tr></tbody></table>

### Virtual Sensors (IaaS)

<table><thead><tr><th width="86.515625">Cloud</th><th width="167.875">VM Type</th><th width="90.953125" align="right">Cores</th><th width="122.22265625" align="right">Memory</th><th width="257.34765625">Storage (OS, Data) in GB)</th><th width="139.95703125">Performance</th></tr></thead><tbody><tr><td>AWS</td><td>r5(n).large</td><td align="right">2</td><td align="right">16 GB</td><td>50, 128</td><td>1 Gbps</td></tr><tr><td>AWS</td><td>r5(n).large</td><td align="right">4</td><td align="right">32 GB</td><td>50, 128</td><td>2 Gbps</td></tr><tr><td>AWS</td><td>r5(n).2xlarge</td><td align="right">8</td><td align="right">64 GB</td><td>50, 512</td><td>4 Gbps</td></tr><tr><td>AWS</td><td>r5(n).4xlarge</td><td align="right">16</td><td align="right">128 GB</td><td>50, 512</td><td>8 Gbps</td></tr><tr><td>AWS</td><td>c5n.18xlarge</td><td align="right">72</td><td align="right">192 GB</td><td>50, 128 (No PCAP capability)</td><td>Up to 10 Gbps</td></tr><tr><td>Azure</td><td>Standard_DS11_v2</td><td align="right">2</td><td align="right">14 GB</td><td>50, 128</td><td>1 Gbps</td></tr><tr><td>Azure</td><td>Standard_DS3_v2</td><td align="right">4</td><td align="right">14 GB</td><td>50, 128</td><td>2 Gbps</td></tr><tr><td>GCP</td><td>e2-standard-2</td><td align="right">2</td><td align="right">8 GB</td><td>50, 128</td><td>1 Gbps</td></tr><tr><td>GCP</td><td>e2-standard-4</td><td align="right">4</td><td align="right">16 GB</td><td>50, 128</td><td>2 Gbps</td></tr><tr><td>GCP</td><td>e2-standard-16</td><td align="right">16</td><td align="right">64 GB</td><td>50, 128</td><td>5 Gbps</td></tr><tr><td>GCP</td><td>e2-standard-32</td><td align="right">32</td><td align="right">128 GB</td><td>50, 128</td><td>10 Gbps</td></tr></tbody></table>

{% hint style="info" %}
**Please note regarding AWS instances:**

AWS vSensor configurations include both “n” and non “n” r5 instance types.

* Networking performance is quoted as “up to 10Gbps” on the r5 instances by AWS and can be influenced by neighboring instances allocated to the same physical hardware in AWS.
* Networking performance is quoted as “up to 25Gbps” on the r5n instances by AWS. These instances are still shared with neighbors but are optimized by AWS to have higher overall network throughput.
* Customers can work with AWS to utilize dedicated instances and distribute instances to provide the required networking throughput to their vSensor instances on that dedicated hardware.

The c5n.18x large vSensor instance type does not have a rolling capture buffer and can therefore not support PCAP generation for Detections that originate from traffic that is processed by those instances.

Due to variability in customer cloud network configurations and how mirroring may configured, it is not possible to guarantee performance on any instance with more than 2 cores (numbers are approximate and based on even distribution of packets across threads). Please contact Vectra to discuss further.

Vectra monitors instance types available from the supported IaaS vendors for cost, performance, and availability. If you have questions about specific instance types that are not supported, please contact your Vectra account team.
{% endhint %}

## Vectra Match Performance

<table><thead><tr><th width="571.83203125">Appliance</th><th width="85.62890625">Mode</th><th width="300.86328125">Match Performanc(Detect and Match)</th></tr></thead><tbody><tr><td>S1</td><td>Sensor</td><td>400 Mbps</td></tr><tr><td>S11</td><td>Sensor</td><td>1.2 Gbps</td></tr><tr><td>S101</td><td>Sensor</td><td>33 Gbps</td></tr><tr><td>S127</td><td>Sensor</td><td>30 Gbps</td></tr><tr><td>X3</td><td>Sensor</td><td>3 Gbps</td></tr><tr><td>X3</td><td>Mixed</td><td>1 Gbps</td></tr><tr><td>X29</td><td>Sensor</td><td>9 Gbps</td></tr><tr><td>X29</td><td>Mixed</td><td>4.6 Gbps</td></tr><tr><td>X47</td><td>Sensor</td><td>13 Gbps</td></tr><tr><td>X47</td><td>Mixed</td><td>6 Gbps</td></tr><tr><td>2 core vSensors (VMware, Hyper-V, KVM, Nutanix)</td><td>Sensor</td><td>250 Mbps</td></tr><tr><td>4 core vSensors (VMware, Hyper-V, KVM, Nutanix)</td><td>Sensor</td><td>500 Mbps</td></tr><tr><td>8 core vSensors (VMware, Hyper-V, KVM, Nutanix)</td><td>Sensor</td><td>1 Gbps</td></tr><tr><td>16 core vSensors (VMware, Hyper-V, KVM, Nutanix)</td><td>Sensor</td><td>2.5 Gbps</td></tr><tr><td>32 core vSensor (VMware)</td><td>Sensor</td><td>10 Gbps</td></tr><tr><td>2 core vSensors (AWS, Azure, GCP)</td><td>Sensor</td><td>500 Mbps</td></tr><tr><td>4 core vSensors (AWS, Azure, GCP)</td><td>Sensor</td><td>1 Gbps</td></tr><tr><td>8 core vSensors (AWS)</td><td>Sensor</td><td>2 Gbps</td></tr><tr><td>16 core vSensors (AWS)</td><td>Sensor</td><td>4 Gbps</td></tr><tr><td>16 core vSensor (GCP)</td><td>Sensor</td><td>2.5 Gbps</td></tr><tr><td>32 core vSensor (GCP)</td><td>Sensor</td><td>5 Gbps</td></tr></tbody></table>

## Stream Sizing and Performance

When considering sizing for Stream it is important to understand that the traffic mix at customer sites varies widely. Some customers have traffic mixes that skew towards larger flows (think file transfers), and some will skew towards smaller flows. Performance will be lower when the traffic mix skews towards smaller flows as there will be more metadata to process. The below are guidelines for average traffic mixes and should not be considered absolute. Throughput refers to the amount of traffic observed by Sensors that forward metadata to the Vectra platform.

**Virtual Appliances:**

<table><thead><tr><th width="138.95703125" align="center">Hypervisor / Cloud</th><th width="162.95703125" align="center">VM Type</th><th width="100" align="center">Cores</th><th width="105.6484375" align="center">Memory</th><th width="98.7421875" align="center">Storage</th><th width="141.7578125" align="center">~ Performance</th></tr></thead><tbody><tr><td align="center">VMware</td><td align="center">vSphere 6.5 or later</td><td align="center">2</td><td align="center">8 GB</td><td align="center">100 GB</td><td align="center">Up to 2.5 Gbps</td></tr><tr><td align="center">VMware</td><td align="center">vSphere 6.5 or later</td><td align="center">4</td><td align="center">8 GB</td><td align="center">150 GB</td><td align="center">2.5 to 5 Gbps</td></tr><tr><td align="center">VMware</td><td align="center">vSphere 6.5 or later</td><td align="center">8</td><td align="center">16 GB</td><td align="center">150 GB</td><td align="center">5 to 10 Gbps</td></tr><tr><td align="center">VMware</td><td align="center">vSphere 6.5 or later</td><td align="center">16</td><td align="center">64 GB</td><td align="center">150 GB</td><td align="center">10 to 20 Gbps</td></tr><tr><td align="center">Hyper-V</td><td align="center">Windows Server 2016 w/ HW v8 or higher</td><td align="center">2</td><td align="center">8 GB</td><td align="center">100 GB</td><td align="center">Up to 2.5 Gbps</td></tr><tr><td align="center">Hyper-V</td><td align="center">Windows Server 2016 w/ HW v8 or higher</td><td align="center">4</td><td align="center">8 GB</td><td align="center">150 GB</td><td align="center">2.5 to 5 Gbps</td></tr><tr><td align="center">Hyper-V</td><td align="center">Windows Server 2016 w/ HW v8 or higher</td><td align="center">8</td><td align="center">16 GB</td><td align="center">150 GB</td><td align="center">5 to 10 Gbps</td></tr><tr><td align="center">Hyper-V</td><td align="center">Windows Server 2016 w/ HW v8 or higher</td><td align="center">16</td><td align="center">64 GB</td><td align="center">500 GB</td><td align="center">10 to 20 Gbps</td></tr><tr><td align="center">KVM</td><td align="center">Standard PC (Q35 + ICH9, 2009)</td><td align="center">2</td><td align="center">8 GB</td><td align="center">100 GB</td><td align="center">Up to 2.5 Gbps</td></tr><tr><td align="center">KVM</td><td align="center">Standard PC (Q35 + ICH9, 2009)</td><td align="center">4</td><td align="center">8 GB</td><td align="center">150 GB</td><td align="center">2.5 to 5 Gbps</td></tr><tr><td align="center">KVM</td><td align="center">Standard PC (Q35 + ICH9, 2009)</td><td align="center">8</td><td align="center">16GB</td><td align="center">150 GB</td><td align="center">5 to 10 Gbps</td></tr><tr><td align="center">KVM</td><td align="center">Standard PC (Q35 + ICH9, 2009)</td><td align="center">16</td><td align="center">64 GB</td><td align="center">500 GB</td><td align="center">10 to 20 Gbps</td></tr><tr><td align="center">AWS</td><td align="center">c5.xlarge</td><td align="center">4</td><td align="center">8 GB</td><td align="center">50 GB</td><td align="center">Up to 5 Gbps</td></tr><tr><td align="center">AWS</td><td align="center">c5.2xlarge</td><td align="center">8</td><td align="center">16 GB</td><td align="center">50 GB</td><td align="center">5 to 10 Gbps</td></tr><tr><td align="center">AWS</td><td align="center">c5.4xlarge</td><td align="center">16</td><td align="center">32 GB</td><td align="center">50 GB</td><td align="center">10 to 20 Gbps</td></tr><tr><td align="center">Azure</td><td align="center">Standard_DS4_v2</td><td align="center">8</td><td align="center">28 GB</td><td align="center">50 GB</td><td align="center">Up to 10 Gbps</td></tr><tr><td align="center">Azure</td><td align="center">Standard_DS5_v2</td><td align="center">16</td><td align="center">56 GB</td><td align="center">50 GB</td><td align="center">10 to 20 Gbps</td></tr><tr><td align="center">GCP</td><td align="center">e2-standard-4</td><td align="center">4</td><td align="center">16 GB</td><td align="center">50 GB</td><td align="center">Up to 5 Gbps</td></tr><tr><td align="center">GCP</td><td align="center">e2-standard-8</td><td align="center">8</td><td align="center">32 GB</td><td align="center">50 GB</td><td align="center">5 to 10 Gbps</td></tr><tr><td align="center">GCP</td><td align="center">e2-standard-16</td><td align="center">16</td><td align="center">64 GB</td><td align="center">50 GB</td><td align="center">10 to 20 Gbps</td></tr></tbody></table>

**Vectra M Series Physical Appliances:**

The M series physical appliances can support up to \~75 Gbps of throughput.

{% hint style="info" %}
**Please Note:**

* Contact your account team or Vectra support for guidance on special situations, abnormal traffic mixes, or throughput needs outside of what is documented above.
* Vectra recommends that Stream VMs are configured to use storage local to the hypervisor and are not stored on a SAN. Stream VMs require extremely high throughput from their disk storage and this throughput cannot normally be sustained by SAN systems without impact to other SAN users.
* Please see [VMware deployment details and considerations](/deployment/ndr-virtual-cloud-appliances/vmware-vsensor/vmware-deployment-details-and-considerations.md) for guidance on supported CPUs, storage/SANs, networking requirements, vMotion, Enhanced vMotion compatibility, and unsupported hypervisors. While Sensor and VMware specific, this article applies to Stream VMs as well. The general guidance in the article also applies to Hyper-V and KVM deployments.
  {% endhint %}

[^1]: For the X29/M29 and X47/M47 appliances, one of the 10 GbE SFP+ ports that are normally used for capture traffic can be configured to be used as a management interface. When configured as such, the original MGT1 copper port would be unused. Please see the quick start guides for these appliances for full details and how to configure the alternate interface configurations.

[^2]: Refers to how many Sensors (physical, virtual, or cloud) an appliance can pair with.

[^3]: Refers to how many hosts the appliance running in Brain or Mixed mode can track simultaneously (open host sessions). Brains can typically retain and display data for larger numbers of hosts, this only refers to how many hosts the system can process metadata for simultaneously.

[^4]: For any appliance that supports SFP interface (SFP+, SFP28, QSFP, QSFP28, etc), please see the SFPs and QSFPs supported in Vectra appliances article on the Vectra support site for additional details and note the following regarding which can be included free as part of your order, or added to your order for an additional cost: Up to 2 (if supported by your appliance model), SFP, SFP+, or SFP28 modules can be included at no additional cost in your appliance order. This is valid for each appliance in your order. Additional SFPs above a count of the two per appliance specified above, will incur additional cost. All 40/100G QSFPs will incur additional cost over the base price of the appliance.

[^5]: For the S1 appliance, both management and capture ports can be configured to use one of the 10 GbE SFP+ ports for either management or capture use. In the default configuration, only the copper interfaces are used. This results in 4 different potential interface configurations for the S1 appliance. Please see the quick start guides for these appliances for full details and how to configure the alternate interface configurations.

[^6]: For the S1v2 one of the 10 GbE SFP+ ports that are normally used for capture traffic can be configured to be used as a management interface. When configured as such, the original MGT1 copper port would be unused.

[^7]: A 2nd power supply can be purchased and used for redundancy.

[^8]: VMware 16-core vSensor storage is shown as `600 GB*` in the source table.

[^9]: This disk has upgraded performance over standard EBS volumes.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.vectra.ai/deployment/getting-started/appliance-specifications.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
