Step 4 (optional). Adding Kaspersky CyberTrace rules

This section describes how you can add Kaspersky CyberTrace rules to LogRhythm manually.

Skip this step, if importing Kaspersky CyberTrace rules and events succeeds.

To add Kaspersky CyberTrace rules to LogRhythm:

  1. Run LogRhythm Console.
  2. Select Deployment Manager > Tools > Knowledge > MPE Rule Builder.

    The Rule Builder form opens.

  3. For every event, add a rule by clicking the Create a new rule button (29).

    For every rule do the following:

    • In the General section, click the button next to the Common Event box and select the required event.

      The event will be displayed in the box.

    • In the Log Message Source Type Associations section, specify Kaspersky CyberTrace as the log source type.
    • To set the rule status, select the Production or Test radio button.

      When creating regular expressions (in the Base-rule Regular Expressions section), follow the instructions provided in the LogRhythm Help section "Use MPE Rule Builder - Parsing Fields and Tags".

      We recommend that you use the regular expressions provided in the table below.

    Rule Builder form

The following list contains regular expressions for each event. If you want to use other regular expressions, use the example events from the second column of the table to check the regular expressions of your choice.

Page top