KUMA services

Services are the main components of KUMA that help the system to manage events: services allow you to receive events from event sources and subsequently bring them to a common form that is convenient for finding correlation, as well as for storage and manual analysis. Each service consists of two parts that work together:

Parts of services are connected to each other via the service ID.

Service types:

In the KUMA web interface, services are displayed in the Resources Active services section in table format. The table of services can be updated using the Refresh button and sorted by columns by clicking on the active headers.

Table columns:

You can use the Add service button to create new services based on existing resource sets for services.

We do not recommend creating services outside the main tenant without first carefully planning the inter-tenant interactions of various services and users.

You can use the buttons in the upper part of the window to do the following:

To change a service, select a service under ResourcesActive services. This opens a window with a set of resources based on which the service was created. You can edit the settings of the set of resources and save your changes. To apply the saved changes, restart the service.

If, when changing the settings of a collector resource set, you change or delete conversions in a normalizer connected to it, the edits will not be saved, and the normalizer itself may be corrupted. If you need to modify conversions in a normalizer that is already part of a service, the changes must be made directly to the normalizer under ResourcesNormalizers in the web interface.

In this section

Services tools

Service resource sets

Creating a storage

Creating a correlator

Creating a collector

Predefined collectors

Creating an agent

Page top