Configuring receipt of Vsftpd events

KUMA allows monitoring Vsftpd events on Linux devices. Events are collected and audited by Vsftpd, after which the events are sent to KUMA via the rsyslog Syslog server.

Configuring the receipt of Vsftpd events involves the following steps:

  1. Configuring audit of Vsftpd events.
  2. Creating a KUMA collector for Vsftpd events.

    When creating a collector in the KUMA web interface, at the Transport step, you need to specify the port and protocol configured for the Syslog server to send events. To receive audit events from Vsftpd, select the [OOTB] Vsftpd syslog normalizer at the Event parsing step.

  3. Installing a collector in the KUMA network infrastructure.
  4. Configuring a Syslog server to send events.
  5. Verifying receipt of Vsftpd events in the KUMA collector

    You can verify that the receipt of events from Vsftpd is configured correctly by searching for related events in the KUMA web interface.

In this section

Configuring audit of Vsftpd events.

Configuring a Syslog server to send Vsftpd events.

Page top