Skip to main content
Following the recommended deployment configuration helps ensure that your LARK appliance operates reliably, captures traffic accurately, and remains accessible to analysts. The guidance below represents best practices gathered from typical operational deployments. Deviating from these recommendations is possible, but may introduce instability, data loss, or reduced visibility.
1

Connect power through a UPS

Place the LARK appliance on a circuit backed by an uninterruptible power supply (UPS). Unexpected power loss can corrupt in-flight captures and on-disk indexes. A UPS provides ride-through time for a clean shutdown and protects against voltage fluctuations common in field environments.
2

Connect via a managed switch, not directly to a laptop

Use a managed switch as the intermediary between the LARK and any analyst laptops or workstations. Direct laptop-to-appliance connections limit access to a single machine and bypass the switch infrastructure needed for VLAN separation, TAP integration, and multi-analyst access. Connect the appliance’s rear connectivity interface to a port on the switch.
If your deployment includes a dedicated local segment, refer to the Naming & Addressing page for the recommended subnet layout.
3

Source traffic from a dedicated TAP, not a SPAN port

Whenever possible, use a dedicated network TAP on the link you want to monitor rather than a SPAN (mirror) port on a switch. SPAN ports can drop packets under load, merge duplex streams incorrectly, and may not accurately reflect line-rate traffic. A passive TAP provides a lossless, full-duplex copy of the monitored link to the LARK ingress port.
If a TAP is not available and a SPAN port must be used, verify that the SPAN configuration mirrors both ingress and egress traffic, and be aware that packet loss is possible under high utilization.
4

Place the appliance on a stable, ventilated surface

Position the LARK on a surface that is physically stable and allows adequate airflow around the chassis. Do not stack objects on top of the unit or block intake and exhaust vents. In rack deployments, ensure adjacent equipment does not recirculate hot exhaust into the LARK’s intake.
5

Configure periodic data offload

Before beginning long-term monitoring, configure the periodic offload or export of captured data to an external destination — such as a NAS, SIEM, or analyst workstation connected through the NIC data export ports. On-appliance storage is finite, and an offload schedule prevents data loss when disk capacity is approached.
6

Change the default admin credentials immediately

After first login, change the default administrative password through the Keycloak admin interface and the system admin panel. Leaving default credentials in place is a significant operational security risk, especially in environments where the LARK is connected to a broader network.
Do not defer credential rotation. Default credentials are documented and known. Change them before placing the appliance on any live network segment.

Configuration Checklist

Use the following checklist to verify your deployment before going live.