In Linux, Kaspersky CyberTrace is installed to the /opt/kaspersky/ktfs directory.
For the Windows installation, the installation directory is hereinafter referred to as %CyberTrace_installDir%.
When you sign in to Kaspersky CyberTrace Web UI for the first time, the Initial Setup Wizard opens. Follow the onscreen instructions. In particular, define the following settings:
At the Proxy settings step of the wizard, If necessary, specify the proxy server connection parameters.
At the Data management settings step of the wizard, specify the following:
Under SIEM system, select Other.
Under Incoming events, specify IP address and port on which Kaspersky CyberTrace will listen for incoming events.
Under Detection alerts, specify IP address and port of McAfee ESM to which Kaspersky CyberTrace will send detection alerts and service alerts.
For McAfee ESM, the port is 514.
On the Settings → Event sources page, click the (Edit) button next to the Default event source, select the Regular expressions tab, and then specify the following regular expressions:
Regular expressions for integration with McAfee ESM