About the distributed integration scheme

Kaspersky CyberTrace supports distributed Splunk environments. The integration scheme for distributed Splunk environments is called the distributed integration scheme.

About the apps and services used in the distributed integration scheme

In the distributed integration scheme, Kaspersky CyberTrace is divided into two apps and one service:

About the integration scheme variants

The following variants of the distributed integration scheme demonstrate a general approach to integrating Kaspersky CyberTrace with your distributed Splunk environment. Depending on how your distributed Splunk environment is organized, you may have to change or combine these variants.

One indexer, multiple forwarders variant

One indexer, multiple forwarders

In the one indexer, multiple forwarders variant, several Heavy or Universal forwarders receive and forward events directly to Feed Service. These forwarders must use Forwarder App (for the respective forwarder type). One of the forwarders receives matches from Feed Service. The forwarder sends the matches to the indexer that stores them in the main index used by Kaspersky CyberTrace for Splunk Search Head App.

Multiple indexers, multiple forwarders variant

In the multiple indexers, multiple forwarders variant, several Heavy or Universal forwarders receive and forward events directly to Feed Service. These forwarders must use Forwarder App (for the respective forwarder type). One of the forwarders receives matches from Feed Service. The forwarder sends the matches to the indexers that store them in the main index used by Kaspersky CyberTrace App.

Default ports and addresses

By default, Forwarder App and Feed Service are configured to use certain addresses and ports for forwarding events and receiving matches. You must change these addresses and ports based on the organization of your distributed Splunk environment.

You must change the default addresses and ports that are used by Forwarder App and Feed Service.

By default, Forwarder App:

By default, Feed Service does the following:

Event format

By default, Kaspersky CyberTrace App and Feed Service are configured to receive events in a certain format:

Page top