Balancer is one of the components of Kaspersky CyberTrace. It runs as a service and allows using Kaspersky CyberTrace in the High Availability mode.
High Availability mode is used when there are several instances of Kaspersky CyberTrace deployed within the same local network.
Since Balancer does not check certificates when establishing HTTPS connections, it is recommended to install it in one network with all CyberTrace instances and the SIEM. To prevent spoofing, the network must be protected from the connection of unauthorized devices.
In High Availability mode, the following features of Kaspersky CyberTrace are supported:
You can use the following REST API requests:
This type of deployment scheme allows you to achieve the following:
Balancer sends incoming events and REST API requests to the instances of Kaspersky CyberTrace where the matching process is performed. Balancer then receives the results of matching by using the ReplyBack mode.
Using Kaspersky CyberTrace in High Availability mode
Requirements and limitations
To ensure that Kaspersky CyberTrace operates properly in High Availability mode, make sure that the following conditions are met:
It is your responsibility to provide the above conditions. Otherwise, the correct operation of Kaspersky CyberTrace in High Availability mode is not guaranteed.
Using Kaspersky CyberTrace in High Availability mode has the following limitations:
AllowedRequests
element in the "Configuring Balancer" section).