Kaspersky Unified Monitoring and Analysis Platform

Configuring the Syslog server to send MongoDB audit events

The Rsyslog service is used to send MongoDB events to the KUMA collector.

To configure the Syslog server to send events:

  1. Create a backup copy of the /etc/rsyslog.conf configuration file.
  2. Edit the /etc/rsyslog.conf file in one of the following ways:
    • To send audit events to the KUMA collector over UDP, add the following line:

      user.info @<IP address of the KUMA collector>:<port of the KUMA collector>

    • To send audit events to the KUMA collector over TCP, add the following line:

      user.info @@<IP address of the KUMA collector>:<port of the KUMA collector>

    MongoDB default values are specified for the syslog severity level and syslog facility level parameters.

  3. Save the changes made to the /etc/rsyslog.conf file.
  4. Restart the Rsyslog service:

    systemctl restart rsyslog.service

The Syslog server is configured to send events.