First Sensor
Sensors are lightweight agents deployed on machines near the infrastructure you want to scan. Each sensor checks in with the central API, receives scanner assignments, and pushes discovered assets back.
Step 1 — Register in the UI
Section titled “Step 1 — Register in the UI”- Navigate to Sensors in the sidebar
- Click Register Sensor
- Enter a name (e.g.,
prod-web-01,dev-laptop,aws-scanner) - Click Register
You’ll see a confirmation with two values:
- Sensor ID — e.g.,
sen_f0cb18b0bc234e8d - API Key — e.g.,
sk_a1b2c3d4e5f6...
Save these immediately. The API key is shown only once.
Step 2 — Install the Sensor
Section titled “Step 2 — Install the Sensor”Option A: Download JAR from the UI
Section titled “Option A: Download JAR from the UI”Click Download JAR on the sensor card (after expanding it). Place the JAR on the target machine.
Option B: Use the install script
Section titled “Option B: Use the install script”Click Install Script on the sensor card. Choose your platform (Linux or Windows). The generated script:
- Downloads the sensor JAR
- Creates
sensor.ymlwith your credentials pre-filled - Sets up a systemd service (Linux) or Windows Service
- Starts the sensor
Option C: Manual setup
Section titled “Option C: Manual setup”Place the sensor JAR on the target machine and create sensor.yml:
apiUrl: https://cbom.yourcompany.comsensorId: sen_f0cb18b0bc234e8dapiKey: sk_a1b2c3d4e5f6...heartbeatInterval: 30sRun it:
java -jar cbom-sensor.jar --config=sensor.ymlStep 3 — Verify Connection
Section titled “Step 3 — Verify Connection”Once the sensor starts, it checks in with the API. Within seconds you should see:
- Sensor status changes to online in the Sensors page
- Hostname and OS are populated automatically
- Sensor logs appear in the expandable card
Configuration Reference
Section titled “Configuration Reference”The sensor.yml file supports:
| Field | Required | Description |
|---|---|---|
apiUrl | Yes | CBOM platform URL (e.g., https://cbom.yourcompany.com) |
sensorId | Yes | Sensor ID from registration |
apiKey | Yes | API key from registration |
heartbeatInterval | No | Check-in interval. Supports: 30s, 1m, 5m, 1h. Default: 5m |
The sensor does not need any scanner configuration in this file — scanners are assigned via the UI and pushed to the sensor on each check-in.
Running as a Service
Section titled “Running as a Service”Linux (systemd)
Section titled “Linux (systemd)”[Unit]Description=CBOM SensorAfter=network.target
[Service]Type=simpleUser=cbom-sensorExecStart=/usr/bin/java -jar /opt/cbom/cbom-sensor.jar --config=/opt/cbom/sensor.ymlRestart=alwaysRestartSec=10
[Install]WantedBy=multi-user.targetWindows (Service)
Section titled “Windows (Service)”Use the generated install script, or configure with sc create:
sc.exe create CbomSensor binPath= "java -jar C:\cbom\cbom-sensor.jar --config=C:\cbom\sensor.yml" start= autosc.exe start CbomSensorNext Steps
Section titled “Next Steps”- Add scanners and run your first scan
- Scanner Reference — All available scanner types