Kaspersky Unified Monitoring and Analysis Platform
Contents
Contents
Configuring receipt of VK WorkSpace Mail events
KUMA allows monitoring VK WorkSpace Mail 1.23 events received in syslog format.
Configuring event receiving consists of the following steps:
- Configuring the export of VK WorkSpace Mail events
- Creating a KUMA collector for VK WorkSpace Mail events.
To receive VK WorkSpace Mail audit events using the Collector Installation Wizard, select the [OOTB] VK WorkSpace Mail syslog normalizer at the Event parsing step. Also, on the Transport tab, you need to specify the port and protocol in accordance with steps 2.2, 2.3 of the Configuring the export of VK WorkSpace Mail events instructions.
- Installing a collector in the KUMA network infrastructure.
- Verifying receipt of VK WorkSpace Mail events in the KUMA collector.
You can verify that the VK WorkSpace Mail event source server is correctly configured in the Searching for related events section of the KUMA web interface.
Configuring the export of VK WorkSpace Mail events
To configure the export of events to KUMA:
- Go to the Settings for duplicating user actions to external storage menu.
- Select the Duplicate user actions to syslog check box.
- In the Syslog server address field, enter the IP address or FQDN of the KUMA collector.
- In the Syslog server port field, specify the port that the KUMA collector is listening on.
- In Syslog protocol, TCP or UDP field, select the communication protocol.
- In the Syslog data ID field, specify bein.
The export of VK WorkSpace Mail events is configured.
Page top