QRadar must treat Kaspersky CyberTrace Service as a log source to receive the events sent by the service. The events sent by Kaspersky CyberTrace Service are in the QRadar Log Event Extended Format (LEEF) format, and the new log source in QRadar will be a Universal LEEF log source.
To add Kaspersky CyberTrace Service to QRadar as a log source:
This name will be displayed in the GUI for any event from this source.
Universal LEEF
in the Log Source Type control.KL_Threat_Feed_Service_v2
. This identifier is used in the EventFormat and AlertFormat parameters.Do not select the Coalescing Events check box. If you select it, all the events from Kaspersky CyberTrace Service will coalesce into a single event that will contain no useful information.
Adding a log source to QRadar
Perform the same actions to add another log source with the KL_Verification_Tool
identifier. It will be used for testing the interaction between Kaspersky CyberTrace Service and QRadar.
After the two log sources are added, select the Admin > Deploy Changes menu item.
Page top