본문으로 건너뛰기

Dell EMC Storage Integration

Overview

Dell EMC provides enterprise storage including PowerStore, Unity, and PowerScale. KYRA MDR collects storage audit logs for monitoring data access and administrative changes.

Prerequisites

  • A KYRA MDR Collector installed and running
  • Dell EMC storage array with administrative access
  • Syslog configured on the storage array
  • Network connectivity from the array to the collector

Configuration

Configure Dell EMC syslog forwarding:

For Dell PowerStore:

  1. Navigate to Settings > Networking > Syslog
  2. Add a syslog server:
SettingValue
ServerYour KYRA Collector IP
Port514
ProtocolTCP
  1. Click Apply

For Dell Unity XT:

  1. Navigate to Settings > Management > Remote Logging
  2. Enable remote syslog

For PowerScale/Isilon:

Terminal window
isi audit settings global modify --syslog-forwarding-enabled true
isi audit settings global modify --config-syslog-servers <collector-ip>

Collected Log Types

Log TypeDescriptionSecurity Use
File AccessFile read and write eventsData access monitoring
Admin OperationsManagement console actionsChange management
AuthenticationLogin and session eventsAccess monitoring
Storage EventsVolume and LUN operationsStorage management
ReplicationData replication eventsData protection monitoring
HardwareHardware health eventsInfrastructure monitoring

Troubleshooting

No syslog events: Verify syslog destination is configured and reachable.

Platform-specific: Each Dell EMC platform has different audit configuration methods.

CEPA for Unity: Dell Unity supports CEPA for detailed file access auditing.

Contact kyra@seekerslab.com for support.