This section describes how you can add Kaspersky CyberTrace rules to LogRhythm manually.
Skip this step, if importing Kaspersky CyberTrace rules and events succeeds.
To add Kaspersky CyberTrace rules to LogRhythm:
The Rule Builder form opens.
For every rule do the following:
The event will be displayed in the box.
Kaspersky CyberTrace
as the log source type.When creating regular expressions (in the Base-rule Regular Expressions section), follow the instructions provided in the LogRhythm Help section "Use MPE Rule Builder - Parsing Fields and Tags".
We recommend that you use the regular expressions provided in the table below.
Rule Builder form
The following list contains regular expressions for each event. If you want to use other regular expressions, use the example events from the second column of the table to check the regular expressions of your choice.
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|
Regular expression |
Event example for checking regular expressions |
|
|