Wazuh Integration with VK Cloud Setup
Wazuh Integration with VK Cloud Setup
Exporting VK Cloud Audit Logs to Wazuh
After you deploy the solution from the VK Cloud Marketplace, all the details required for the connection are sent to the email address of the user who submitted the installation request.
The solution will be fully ready to work with security events. To start receiving VK Cloud audit events, do the following:
- Open the VK Cloud web interface and select the desired project.
- Go to the
Мониторинг(Monitoring) –>Журнал событий(Event Log) section. - Select
Настройки(Settings). - Click
Создать подключение(Create connection) and fill in the fields:Название(Name) - as you preferТочка подключения(Connection endpoint) - the external IP address of the Wazuh server (if an HA setup is used, the IP address of the Wazuh Worker) and port514
- In the
Протокол передачи данных(Data transfer protocol) field, select TCP. - In the
Формат сообщения(Message format) field, selectCEF. - Click
Создать(Create). - In the window that appears, click
Активировать(Activate).
Note: At this time we support only audit logs in CEF (Common Event Format).
After these steps, VK Cloud events will start appearing in the Wazuh web interface.
Reviewed by OpenNix LLC · Last updated on