Commvault Integration
Overview
Commvault provides enterprise data protection across on-premises and cloud environments. KYRA MDR collects Commvault audit logs for monitoring backup operations and administrative actions. Supports Commvault V11 and Platform Release 2023+.
Prerequisites
- A KYRA MDR Collector installed and running
- Commvault CommServe with administrative access
- Commvault Audit Trail enabled
- Network connectivity from CommServe to the collector
Configuration
Configure Commvault audit log forwarding:
- Enable Audit Trail in Control Panel > Audit Trail
- Configure syslog under Control Panel > Alerts > Alert Definitions:
- Create an alert for audit events
- Set notification to Syslog
| Setting | Value |
|---|---|
| Syslog Server | Your KYRA Collector IP |
| Port | 514 |
| Protocol | TCP |
| Format | CEF |
- For API-based collection:
sources: - type: commvault api_url: https://<commserve>:81/SearchSvc/CVWebService.svc username: <api-user> password: <password> poll_interval: 3600sCollected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Backup | Backup job execution events | Data protection monitoring |
| Restore | Data restore operations | Recovery auditing |
| Login | Console and API login events | Access monitoring |
| Configuration | Policy and setting changes | Change management |
| Data Access | Data browse and download events | Data exfiltration monitoring |
| Compliance | Retention and compliance events | Regulatory compliance |
Troubleshooting
Audit Trail not available: Ensure the feature is enabled in CommServe configuration.
Missing backup events: Verify the alert definition includes backup job events.
REST API pagination: The collector handles pagination automatically.
Contact kyra@seekerslab.com for support.