Creating notifications about incoming service events

April 11, 2024

ID 196832

You can create notifications about incoming Kaspersky CyberTrace service events by configuring alert rules.

To create notifications about service events from Kaspersky CyberTrace in ArcSight ESM:

  1. Run ArcSight Console.
  2. In the Navigator pane, select Rules in the drop-down-list.
  3. In the tree view, select the Rules > Shared > All Rules > Public directory.

    Rules tree view in ArcSight.

    The Rules tree view

  4. Right-click the filter node in the Kaspersky CyberTrace Connector tree and select New Rule > Standard Rule.
  5. In the Inspect > Edit pane, specify the following settings:
    • In the Name field of the Attributes tab, specify the name of the rule.

      You can specify any name.

    • On the Conditions tab, specify the following conditions:
      • Device Product = Kaspersky CyberTrace for ArcSight
      • Reason = %ServiceEventCode%

        Where %ServiceEventCode% is a code of a service event that is used for generating notifications.

    Event conditions in ArcSight.

    Event conditions

    • Right-click the Actions tab, choose On Every Event and then select the following:
      • Activate Trigger
      • Add

        This setting must contain the action that will be performed when a service event that is specified on the Conditions tab is received. For example, Send Notification.

    Add "Send Notification" Action window in ArcSight.

    Adding actions

  6. Click Apply.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.