This section describes how to configure retrieval of custom event properties from Kaspersky CyberTrace outgoing events in addition to standard fields. This configuration enables the MD5, SHA1, and SHA256 hashes to be extracted and the extraction rule of the Source IP field will be redefined.
To configure retrieval of custom event properties:
The Add Filter form opens.
Log Source [Indexed].KL_Threat_Feed_Service_v2.The KL_Threat_Feed_Service_v2 selection is the log source name that is set in the OutputSettings > EventFormat element and the OutputSettings > AlertFormat element of the Feed Service configuration file (you can also set them by using Kaspersky CyberTrace Web).

Adding a filter
) in the upper-right area of the window.
The Log Activity window
The DSM Editor window opens.

The DSM Editor window
The Choose a Custom Property Definition to Express form opens.

Choosing a custom property
The Create a new Custom Property Definition form opens.
MD5.Text.
Creating a new custom property definition
SHA1, SHA256, URL and IP properties in the same way.Event NameIP (custom)MD5 (custom)SHA1 (custom)SHA256 (custom)Source IPURL (custom)Username
Configuring preview columns
Custom property |
Regular expression |
MD5 |
|
SHA1 |
|
SHA256 |
|
URL |
|
Source IP |
|
IP |
|
For the MD5, SHA1, SHA256, URL and IP custom properties, specify 1 in the Capture Group field. For the Source IP property, specify $1 in the Format String field.

Source IP configuration
When changing the format for outgoing detection events in Kaspersky CyberTrace, the regular expressions that are specified above may require corresponding changes.
If all the setings above are specified correctly, you will find the configured Custom properties in the Log Activity Preview section.
If you now open the event received from KL_Threat_Feed_Service_v2, the configured custom properties will be displayed.

Event information