# Log Collector Installation - Onboarding "Let's Go" (OLD)

#### <span style="color: rgb(53, 152, 219);">**Log Collector Installation in CyTech - AQUILA**</span>

<span style="color: rgb(0, 0, 0);">This guide outlines the step-by-step process for deploying the **Elastic Agent** as a log collector within the **CyTech - AQUILA** environment. Following these instructions will establish a secure and automated mechanism for log collection and management, enabling centralized visibility and analysis critical to cybersecurity operations.</span>

#### <span style="color: rgb(53, 152, 219);">**Pre-requisites**</span>

1. <span style="color: rgb(0, 0, 0);">**Access to CyTech - AQUILA**</span>
    - <span style="color: rgb(0, 0, 0);">Only users assigned the **"Owner"** or **"Admin"** role can access the Log Collector installation resources within the platform.</span>
2. <span style="color: rgb(0, 0, 0);">**Dedicated Virtual Machine for Log Collector Deployment**</span>
    - <span style="color: rgb(0, 0, 0);">**Dedicated Unit**: It is recommended to use a separate, dedicated VM exclusively for the Log Collector to prevent resource contention and ensure stable performance.</span>
    - <span style="color: rgb(0, 0, 0);">**Virtual Machine (VM) Preferred**: Deploying the Log Collector on a VM offers greater flexibility, scalability, and easier maintenance compared to physical hardware.</span>
    - <span style="color: rgb(0, 0, 0);">**Always Online**: The virtual machine must remain continuously online to ensure uninterrupted log collection from all integrated sources.</span>

<p class="callout info"><span style="color: rgb(0, 0, 0);">For the full Log Collector Hardware Requirements Guide, please refer to this link:<span style="color: rgb(224, 62, 45);"> [Log Collector Hardware Requirements Guide](https://docs.cytechint.io/books/log-collector-installations/page/log-collector-hardware-requirements-guide "Log Collector Hardware Requirements Guide")</span></span></p>

##### **Steps to Add Log Collector**

<span style="color: rgb(0, 0, 0);">Please follow the steps below to add a Log Collector using Windows Environment.</span>

1. <span style="color: rgb(0, 0, 0);">Log in to **CyTech - AQUILA**. Click here: **[AQUILACYBER.AI](https://aquilacyber.ai/)**</span>

- <span style="color: rgb(0, 0, 0);">Click **Collapse** to view side panel. Then navigate through **Domains&gt;Cyber Monitoring&gt;Cyber Incident Management (CIM)&gt;Dashboard**.</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/7XSNFwzpOYPFH9L4-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/7XSNFwzpOYPFH9L4-image.png)

<span style="color: rgb(0, 0, 0);">2. In the **Cyber Incident Management (CIM) Dashboard**, scroll to the bottom and click the "**<span style="color: rgb(53, 152, 219);">Let’s Go</span>"** button to initiate the Log Collector installation interface.</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/scaled-1680-/YB0Y07lltzhWSdy8-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-06/YB0Y07lltzhWSdy8-image.png)

<span style="color: rgb(0, 0, 0);">3. Once the installation window display is shown, click "<span style="color: rgb(53, 152, 219);">**Next**</span>" to proceed.</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-04/scaled-1680-/fv6BrPkUqqVpruL3-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-04/fv6BrPkUqqVpruL3-image.png)

<div ccp_infra_copy_id="" ccp_infra_timestamp="1730881565624" ccp_infra_user_hash="1723791988" ccp_infra_version="3" data-ccp-timestamp="1730881565624" id="bkmrk-4.-carefully-review-"><span style="color: rgb(0, 0, 0);">4. Thoroughly review the **System Requirements** specific to your operating system to ensure compatibility and avoid installation or runtime issues. Verifying these prerequisites is essential before proceeding with deployment. Then click "<span style="color: rgb(53, 152, 219);">**Next**</span>".</span></div><p class="callout info"><span style="color: rgb(0, 0, 0);">You can also refer to our documentation manuals for Log Collector Installations Guidelines:<span style="color: rgb(224, 62, 45);"> </span></span><span style="color: rgb(224, 62, 45);">[https://docs.cytechint.io/books/log-collector-installations](https://docs.cytechint.io/books/log-collector-installations "https://docs.cytechint.io/books/log-collector-installations")</span></p>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-04/scaled-1680-/cMFarJ014TLfykzx-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-04/cMFarJ014TLfykzx-image.png)

<span style="color: rgb(0, 0, 0);">5. From the options, select the "<span style="color: rgb(53, 152, 219);">**Automatic**</span>" installation option. Then click "<span style="color: rgb(53, 152, 219);">**Next**</span>".</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/AQSi4pI6aMzhgE5U-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/AQSi4pI6aMzhgE5U-image.png)

<div ccp_infra_copy_id="" ccp_infra_timestamp="1730881819587" ccp_infra_user_hash="1723791988" ccp_infra_version="3" data-ccp-timestamp="1730881819587" id="bkmrk-6.-carefully-follow-"><span style="color: rgb(0, 0, 0);">6.</span> <span style="color: rgb(0, 0, 0);">Carefully follow the instructions for the Automatic Installation.</span></div><span style="color: rgb(0, 0, 0);">6a. Download the Windows Installer.</span>

<div ccp_infra_copy_id="" ccp_infra_timestamp="1730881819587" ccp_infra_user_hash="1723791988" ccp_infra_version="3" data-ccp-timestamp="1730881819587" id="bkmrk-click-on-the-%22downlo">- <span style="color: rgb(0, 0, 0);">Click on the **"<span style="color: rgb(53, 152, 219);">Download Installer</span>"** button to download the Windows MSI Package for Elastic Agent. </span>
- <span style="color: rgb(0, 0, 0);">The URL can also be found on</span> [https://artifacts.elastic.co/downloads/beats/elastic-agent/elastic-agent-8.15.1-windows-x86\_64.msi](https://artifacts.elastic.co/downloads/beats/elastic-agent/elastic-agent-8.15.1-windows-x86_64.msi)

</div>[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/m7BWhjfRdH8ohzjK-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/m7BWhjfRdH8ohzjK-image.png)

<span style="color: rgb(0, 0, 0);">6b. Ensure that the Elastic Agent file is located in your Downloads folder before proceeding.</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/vpK02FpDmidLAKOC-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/vpK02FpDmidLAKOC-image.png)

<span style="color: rgb(0, 0, 0);">6c. **Copy the commands** provided on the installation page and execute them sequentially to ensure successful execution. These commands are required to complete the log collector installation in the subsequent steps.</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/sowVOCRDTrgJf7bk-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/sowVOCRDTrgJf7bk-image.png)

<span style="color: rgb(0, 0, 0);">7. In your dedicated environment for your Log Collector, open the **Command Prompt** and run as **Administrator**.</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-04/scaled-1680-/IvL5O3f5LMaWdvfC-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-04/IvL5O3f5LMaWdvfC-image.png)

<div ccp_infra_copy_id="" ccp_infra_timestamp="1730882195141" ccp_infra_user_hash="1723791988" ccp_infra_version="3" data-ccp-timestamp="1730882195141" id="bkmrk-8.-execute-the-comma"><span style="color: rgb(0, 0, 0);">8. Execute the commands displayed in **Figure 6b** as shown in the manual.</span></div><div ccp_infra_copy_id="" ccp_infra_timestamp="1730882195141" ccp_infra_user_hash="1723791988" ccp_infra_version="3" data-ccp-timestamp="1730882195141" id="bkmrk-for-example-%28elastic">- <span style="color: rgb(0, 0, 0);">For example (elastic-agent-&lt;VERSION&gt;-windows-x86\_64.msi INSTALLARGS="--url=&lt;URL&gt; --enrollment-token=&lt;TOKEN&gt;").</span>
- <span style="color: rgb(0, 0, 0);">Once the commands are executed successfully, you should see an output similar to the example shown in the image below.</span>

</div>[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/AUgMFbn3c2qfPKWG-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/AUgMFbn3c2qfPKWG-image.png)

<span style="color: rgb(0, 0, 0);">8a. **The Elastic Agent installation window will appear.** Check the **“I accept the terms in the license agreement”** box, then click **Install**.</span>  
<span style="color: rgb(0, 0, 0);">Wait for the installation to complete, and then click **Finish**.</span>

<span style="color: rgb(0, 0, 0);">[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/8ti6ZlQXsr638myL-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/8ti6ZlQXsr638myL-image.png)[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/zS08rBb67HeWDdyj-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/zS08rBb67HeWDdyj-image.png)</span>

<span style="color: rgb(0, 0, 0);">9. Before proceeding with the final installation setup, ensure all required steps have been completed by clicking the check box. Once confirmed, click “**Next**” to continue.</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/scaled-1680-/KKTS2UmY4cynKBqc-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-05/KKTS2UmY4cynKBqc-image.png)

<span style="color: rgb(0, 0, 0);">10. Allow 3–5 minutes for the Log Collector Agent to complete registration and report its "**<span style="color: rgb(45, 194, 107);">Online</span>"** status to the fleet server, indicating a successful installation.</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-04/scaled-1680-/vXy84bmBUjBhNmPg-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-04/vXy84bmBUjBhNmPg-image.png)

<span style="color: rgb(0, 0, 0);">11. This step confirms the successful installation and enrollment of the Log Collector Agent with the fleet server. The interface will display the Log Collector host name and the user who performed the installation. Click "**<span style="color: rgb(53, 152, 219);">Continue</span>"** to complete the setup process.</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-04/scaled-1680-/QV0YRCuqiPqQjtAr-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-04/QV0YRCuqiPqQjtAr-image.png)

<span style="color: rgb(0, 0, 0);">12. Also you can verify successful installation by going to **Cyber Incident Monitoring&gt;Settings&gt;Log Collector**.</span>

- <span style="color: rgb(0, 0, 0);">In the Log Collector List, you can see all the log collector installed. You can also view the Log Collector details such us: **Agent Name, Status and IP address**.</span>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-04/scaled-1680-/E17yVLWccJaInPG1-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-04/E17yVLWccJaInPG1-image.png)

<p class="callout warning">*\*\*\*If you encounter <span style="color: rgb(224, 62, 45);">**Log Collector Setup Failed**</span>. Please click "Retry" and carefully go gack to Steps 5 or 6. You can also try "**Manual**" installation. If issues persist please contact our technical support at **<support@cytechint.com>** for prompt assistance and guidance.*</p>

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-04/scaled-1680-/uEYotwkAJTB5YZKK-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2025-04/uEYotwkAJTB5YZKK-image.png)

 *If you need further assistance, kindly contact our technical support at **<support@cytechint.com>** for prompt assistance and guidance.*