Kaspersky Unified Monitoring and Analysis Platform

Diode type

The diode type is used to transmit events using a data diode.

Available settings:

Basic settings tab:

  • Name (required)—a unique name for this type of resource. Must contain from 1 to 128 Unicode characters.
  • Tenant (required)—name of the tenant that owns the resource.
  • Disabled toggle switch—used if you do not need to send events to a destination. By default, sending events is enabled.
  • Type (required) – destination type, diode.
  • Data diode source directory (required)—the directory from which the data diode transfers events. The path can contain up to 255 Unicode characters.

    Limitations when using prefixes in paths on Windows servers

    Limitations when using prefixes in paths on Linux servers

  • Temporary directory—directory in which events are prepared for transmission to the data diode.

    Events are collected in a file when a timeout (10 seconds by default) or a buffer overflow occurs. The prepared file is moved to the directory specified in the Data diode source directory field. The checksum (SHA-256) of the file contents is used as the name of the file containing events.

    The temporary directory must be different from the data diode source directory.

  • Description—up to 256 Unicode characters describing the resource.

Advanced settings tab:

  • Compression—you can use Snappy compression. By default, compression is disabled.

    This setting must match for the connector and destination resources used to relay events from an isolated network segment via the data diode.

  • Buffer size is used to set the size of the buffer. Default size is 64 MB. It cannot exceed 64 MB.
  • Timeout—field in which you can specify the interval (in seconds) at which the data is moved from the temporary directory to the directory for the data diode. The default value is 10.
  • Delimiter is used to specify the character delimiting the events. By default, \n is used.

    This setting must match for the connector and destination resources used to relay events from an isolated network segment via the data diode.

  • Buffer flush interval—this field is used to set the time interval (in seconds) at which the data is sent to the destination. The default value is 100.
  • Workers—this field is used to set the number of services processing the queue. By default, this value is equal to the number of vCPUs of the KUMA Core server.
  • Debug—a drop-down list where you can specify whether resource logging should be enabled. By default it is Disabled.
  • The Disk buffer disabled drop-down list is used to enable or disable the use of a disk buffer. By default, the disk buffer is disabled.
  • In the Filter section, you can specify the conditions to define events that will be processed by this resource. You can select an existing filter resource from the drop-down list, or select Create new to create a new filter.

    Creating a filter in resources