To install the launcher and sensor on a Linux VM, you run a recovery plan, start the VM, install the Carbon Black Cloud launcher, and then install the sensor.

When you run a recovery plan and start the VM on the recovery SDDC, you are prompted to install the sensor. At this point in the plan, you can install the launcher and then install the sensor on the Linux VM.

You have two methods of installing the sensor on a Linux VM:
  • Log into the recovery SDDC vCenter and Enable Carbon Black on Virtual Machines (steps 1 through 7 in this task). Use this option if you do not have access to the Carbon Black Cloud service tile, or if you are a partner using the Cloud Provider Network (CPN) console
  • Use the Carbon Black Cloud security console. This method requires having access to the Carbon Black Cloud console, which requires at least one Carbon Black Cloud user role. For more information, see Predefined User Roles.

Procedure

  1. Start the plan by clicking the Ransomware Recovery button.
  2. In the VMs list of the plan, click the Linux VM.
  3. In the Ransomware recovery page, click Start Ransomware Recovery.
  4. On the ransomware recovery iteration page, click the Start VM in Recovery SDDC button.
  5. In the Validate VM in recovery SDDC dialog box, select a snapshot of the VM you want to analyze. Then, click Start VM In Recovery SDDC.
  6. As the VM starts, the system pauses the VM recovery so you can install the Linux sensor. Under Start VM, you see the following:
    Message asking you to install the Linux sensor.
  7. If you are installing the sensor manually using the recovery SDDC vCenter, follow the steps to Enable Carbon Black on Virtual Machines. You do not need to follow the remaining steps in this task.
  8. If you are using the Carbon Black Cloud console to install the sensor, first follow these instructions to install the Carbon Black Launcher for Linux VMs.
  9. Then, open the Carbon Black Cloud console and navigate to your VMware Cloud organization home page and click the Carbon Black Cloud tile.
    Note: Opening the Carbon Black Cloud console requires at least one Carbon Black Cloud user role.
  10. In the Carbon Black Cloud console, browse to Inventory > VM Workloads.
  11. Select the Not Enabled tab.
  12. Next, select the Eligible check box next to the VM, and then from the Take Action menu, select Install Sensors.
    Menu item to open VM in Carbon Black Cloud security console.
  13. In the Install Sensor dialog box, click the Install button.
  14. When the sensor finishes installing, return to the VMware Live Cyber Recovery UI. You do not need to restart the VM.

What to do next

Now that you have installed the sensor, integrated security and vulnerability analysis starts on the VM.