This section describes the actions to perform so that a new log source pertaining to Kaspersky CyberTrace will appear in LogRhythm. If LogRhythm is already configured properly, you do not need to take action, as the new log source will appear in LogRhythm and you only have to check that everything is as you specified.
To create conditions for a log source pertaining to Kaspersky CyberTrace to be added to LogRhythm:
The System Monitor Agent Properties window opens.
System Monitor Agent Properties window
The Data Processor Advanced Properties window opens.
Data Processor Advanced Properties window
LogRhythm will inform you whether a restart is required.
After Kaspersky CyberTrace sends an event, a new item appears on the Log Sources tab.
To accept the new log source:
The Log Source Acceptance Properties window opens.
Log Source Acceptance Properties window
Kaspersky CyberTrace
as the log source type.The entity name must be unique and non-empty. Other entity properties can be arbitrary.
Log source context menu
The new log source now appears in the lower table in LogRhythm Console.
New log source
Disabling log forwarding for the events received from Kaspersky CyberTrace
You may need to disable log forwarding for the events received from Kaspersky CyberTrace, to avoid the looping of events, which is forwarding the received events back to Kaspersky CyberTrace.
To disable log forwarding for the events received from Kaspersky CyberTrace:
Editing the properties of the Kaspersky CyberTrace log source
Specifying the log message processing mode
In the MPE Processing Mode column, No Event Forwarding will be displayed for the selected log source.
The MPE Processing Mode column
Page top