1
Connect power through a UPS
Place the LARK appliance on a circuit backed by an uninterruptible power supply (UPS). Unexpected power loss can corrupt in-flight captures and on-disk indexes. A UPS provides ride-through time for a clean shutdown and protects against voltage fluctuations common in field environments.
2
Connect via a managed switch, not directly to a laptop
Use a managed switch as the intermediary between the LARK and any analyst laptops or workstations. Direct laptop-to-appliance connections limit access to a single machine and bypass the switch infrastructure needed for VLAN separation, TAP integration, and multi-analyst access. Connect the appliance’s rear connectivity interface to a port on the switch.
If your deployment includes a dedicated local segment, refer to the Naming & Addressing page for the recommended subnet layout.
3
Source traffic from a dedicated TAP, not a SPAN port
Whenever possible, use a dedicated network TAP on the link you want to monitor rather than a SPAN (mirror) port on a switch. SPAN ports can drop packets under load, merge duplex streams incorrectly, and may not accurately reflect line-rate traffic. A passive TAP provides a lossless, full-duplex copy of the monitored link to the LARK ingress port.
4
Place the appliance on a stable, ventilated surface
Position the LARK on a surface that is physically stable and allows adequate airflow around the chassis. Do not stack objects on top of the unit or block intake and exhaust vents. In rack deployments, ensure adjacent equipment does not recirculate hot exhaust into the LARK’s intake.
5
Configure periodic data offload
Before beginning long-term monitoring, configure the periodic offload or export of captured data to an external destination — such as a NAS, SIEM, or analyst workstation connected through the NIC data export ports. On-appliance storage is finite, and an offload schedule prevents data loss when disk capacity is approached.
6
Change the default admin credentials immediately
After first login, change the default administrative password through the Keycloak admin interface and the system admin panel. Leaving default credentials in place is a significant operational security risk, especially in environments where the LARK is connected to a broader network.