Kaspersky Unified Monitoring and Analysis Platform
Configuring CyberTrace to receive and process requests

You can configure CyberTrace to receive and process requests from KUMA immediately after its installation in the Quick Start Wizard or later in the application web interface.

To configure CyberTrace to receive and process requests in the Quick Start Wizard:

  1. Wait for the CyberTrace Quick Start Wizard to start after the application is installed.

    The wizard starts at step 1, Welcome to Kaspersky CyberTrace. You can go to the next step of the wizard by clicking Next.

  2. At step 2, Proxy settings, if your organization uses a proxy server, enter its connection settings. If your organization does not use a proxy server, leave all fields blank.
  3. At step 3, Licensing settings, select the method for adding a license key for CyberTrace: an activation code or a license key file. Depending on the selected method, specify the activation code or upload a license key file.
  4. At step 4, Service settings, keep default settings.
  5. At step 5, Data management settings:
    1. In the SIEM system drop-down list, select KUMA.
    2. Under Listen on, select the IP and port option.
    3. In the IP address field, enter 0.0.0.0.
    4. In the Port field, enter the port to listen on for events. The default port is 9999.
    5. Under Send detection alerts, in the IP address field, enter 127.0.0.1, and in the Port field, enter 9998.

    Leave the default values for everything else.

  6. At step 6, Certificate settings, select Commercial certificate and add a certificate that allows you to download data feeds from update servers.
  7. At step 7, Feeds settings, keep default settings.

CyberTrace is configured.

To configure CyberTrace to receive and process requests in the application web interface:

  1. In the window of the CyberTrace web interface, switch Data management mode: in the left menu, select System, and then in the displayed menu, select General.
  2. Select the Settings → General section.
  3. Under Listen on:
    1. Select IP and port.
    2. In the IP address field, enter 0.0.0.0.
    3. In the Port field, enter the port to listen on for events. The default port is 9999.
  4. Select the Settings → Service alerts section.
  5. In the Service alert format field, enter %Date% alert=%Alert%%RecordContext%.
  6. In the Records context format field, enter |%ParamName%=%ParamValue%.
  7. Select the Settings → Detection alerts section.
  8. In the Alert format field, enter Category=%Category%|MatchedIndicator=%MatchedIndicator%%RecordContext%.
  9. On the Context tab, in the Actionable fields field, enter %ParamName%:%ParamValue%.
  10. Switch to the System management mode: in the left menu, select General, then in the displayed menu, select System.
  11. Select the Settings → Service section.
  12. Under Web interface, in the IP address or host name, enter 127.0.0.1.
  13. In the upper toolbar, click Restart service.
  14. Restart the CyberTrace server.

CyberTrace is configured.