Tenants settings
Kaspersky CyberTrace supports a multi-tenant architecture that allows you to manage tenants. A tenant is a client-specific set of configuration parameters. By default, Kaspersky CyberTrace uses a General tenant that provides the overall settings. You can create or edit the Kaspersky CyberTrace tenants in CyberTrace Web by selecting the Settings tab, and then the Tenants tab.
On the Tenants tab, you can view information about the tenants that are used in Kaspersky CyberTrace and perform the following actions:
- Add a new tenant
- Edit a tenant configuration
- Delete a tenant
Adding tenants
To add a tenant:
- Click the Add new tenant link.
The New tenant window opens.
- Specify a name for the new tenant in the Tenant field.
- Specify a description for this tenant in the Description field.
- Select a SIEM.
You can select a SIEM supported by Kaspersky CyberTrace or a custom one (a non-supported SIEM solution).
This SIEM will be used in the tenant for sending events to CyberTrace.
Depending on the selected SIEM, CyberTrace will specify regular expressions, detection events, and service events that are used in integration with this solution.
For the full list of supported SIEMs, see subsection "Supported SIEM solutions" below.
- Specify connection parameters specific for the tenant that Kaspersky CyberTrace will use for incoming events:
- Select what type of connection you want to use.
- In the IP address and Port fields, specify an IP address and port.
- In the UNIX socket field, specify a UNIX socket.
- Specify an IP address and port specific for the tenant that Kaspersky CyberTrace will use for outgoing events.
- Click Save.
Editing a tenant configuration
To edit a tenant configuration:
- Click the Edit button next to the tenant that you want to edit.
- Edit the tenant configuration:
- Tenant name
You cannot change the tenant name for the General tenant.
- Description
- Tenant name
- Click Save.
Deleting tenants
To delete a tenant:
- Click Delete next to the tenant that you want to delete.
- Confirm that you want to delete the tenant.
Supported SIEM solutions
Kaspersky CyberTrace supports integration with several SIEM solutions. Thus, CyberTrace uses a number of preset settings for each SIEM, such as settings for parsing events and event format settings (for detection and service events).
The following SIEM solutions are supported:
- Splunk
- ArcSight ESM
- RSA NetWitness
- IBM QRadar
- LogRhythm
- Kaspersky Unified Monitoring and Analysis Platform