> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cyberup24.com/llms.txt
> Use this file to discover all available pages before exploring further.

# LARK Models

The LARK is available in three models — SWIFT, PEREGRINE, and APEX — each sized for a different deployment scale. All three run the same software stack and work the same way operationally, so the choice between them is purely a question of how much traffic you need to handle, how long you need to retain data on-appliance, and how large your monitored environment is. This page describes what distinguishes the three models so you can confirm you have the right one for your use case.

## Shared software foundation

All three LARK models run an identical software stack: the same containerized services, the same orchestration layer, the same analyst tools, and the same onboard AI layer. There is no feature difference between models. A workflow you develop on a SWIFT works exactly the same way on an APEX.

<Note>
  All three models are operationally identical. Unless a page in this documentation explicitly calls out a model-specific difference, every procedure, configuration, and reference here applies to SWIFT, PEREGRINE, and APEX equally.
</Note>

## Models at a glance

| Model     | Nodes          | Positioning                                                            |
| --------- | -------------- | ---------------------------------------------------------------------- |
| SWIFT     | Single node    | Entry capacity for smaller networks and focused monitoring             |
| PEREGRINE | Single node    | Mid-range capacity for sustained monitoring and heavier analysis       |
| APEX      | Multiple nodes | Highest capacity and throughput for large or high-traffic environments |

## SWIFT

The SWIFT is a single-node appliance built for entry-level capacity. It is the right choice when you are monitoring a smaller network, a specific segment, or a focused subset of traffic where the sustained volume is relatively low. Typical deployments include branch offices, isolated lab environments, dedicated segment monitoring, and situations where you need a quickly deployable unit for a time-limited engagement.

## PEREGRINE

The PEREGRINE is a single-node appliance at the mid-range of the product line. It is designed for sustained, long-running monitoring workloads and supports heavier analytical tasks alongside continuous capture. It suits environments where traffic volumes are moderate to significant and where analysts are running more intensive queries, correlations, or AI-assisted workflows against a larger accumulated dataset.

## APEX

The APEX is the highest-capacity model in the LARK line. Unlike the SWIFT and PEREGRINE, the APEX spans multiple nodes, which allows it to distribute capture, processing, storage, and AI inference across its cluster. This architecture is suited to large networks, high-traffic environments, or deployments where you need both maximum throughput at the capture layer and substantial on-appliance retention. From an operational standpoint the APEX presents as a single system; the multi-node architecture is managed internally by the orchestration layer.

## Hardware specifications

<Note>
  Specific hardware specifications — including CPU, RAM, and storage capacity — for each model are provided on the delivery record that ships with your unit. Refer to that document for the exact configuration of your appliance.
</Note>
