Configuring receipt of ProFTPD events

KUMA allows monitoring ProFTPD events on Linux devices. Events are collected and audited by ProFTPD, after which the events are sent to KUMA via the rsyslog Syslog server.

Configuring the receipt of ProFTPD events involves the following steps:

  1. Configuring audit of ProFTPD events.
  2. Creating a KUMA collector for ProFTPD events.

    When creating a collector in the KUMA web interface, at the Transport step, you need to specify the port and protocol configured for the Syslog server to send events. To receive audit events from ProFTPD, select the [OOTB] Proftpd syslog normalizer at the Event parsing step.

  3. Installing a collector in the KUMA network infrastructure.
  4. Configuring a Syslog server to send events.
  5. Verifying receipt of ProFTPD events in the KUMA collector

    You can verify that the receipt of events from ProFTPD is configured correctly by searching for related events in the KUMA web interface.

In this section

Configuring audit of ProFTPD events.

Configuring a Syslog server to send ProFTPD events.

Page top