跳至正文

Commvault Integration

Overview

Commvault provides enterprise data protection across on-premises and cloud environments. KYRA MDR collects Commvault audit logs for monitoring backup operations and administrative actions. Supports Commvault V11 and Platform Release 2023+.

Prerequisites

  • A KYRA MDR Collector installed and running
  • Commvault CommServe with administrative access
  • Commvault Audit Trail enabled
  • Network connectivity from CommServe to the collector

Configuration

Configure Commvault audit log forwarding:

  1. Enable Audit Trail in Control Panel > Audit Trail
  2. Configure syslog under Control Panel > Alerts > Alert Definitions:
    • Create an alert for audit events
    • Set notification to Syslog
SettingValue
Syslog ServerYour KYRA Collector IP
Port514
ProtocolTCP
FormatCEF
  1. For API-based collection:
collector-config.yaml
sources:
- type: commvault
api_url: https://<commserve>:81/SearchSvc/CVWebService.svc
username: <api-user>
password: <password>
poll_interval: 3600s

Collected Log Types

Log TypeDescriptionSecurity Use
BackupBackup job execution eventsData protection monitoring
RestoreData restore operationsRecovery auditing
LoginConsole and API login eventsAccess monitoring
ConfigurationPolicy and setting changesChange management
Data AccessData browse and download eventsData exfiltration monitoring
ComplianceRetention and compliance eventsRegulatory compliance

Troubleshooting

Audit Trail not available: Ensure the feature is enabled in CommServe configuration.

Missing backup events: Verify the alert definition includes backup job events.

REST API pagination: The collector handles pagination automatically.

Contact kyra@seekerslab.com for support.