Dell EMC Storage Integration
Overview
Dell EMC provides enterprise storage including PowerStore, Unity, and PowerScale. KYRA MDR collects storage audit logs for monitoring data access and administrative changes.
Prerequisites
- A KYRA MDR Collector installed and running
- Dell EMC storage array with administrative access
- Syslog configured on the storage array
- Network connectivity from the array to the collector
Configuration
Configure Dell EMC syslog forwarding:
For Dell PowerStore:
- Navigate to Settings > Networking > Syslog
- Add a syslog server:
| Setting | Value |
|---|---|
| Server | Your KYRA Collector IP |
| Port | 514 |
| Protocol | TCP |
- Click Apply
For Dell Unity XT:
- Navigate to Settings > Management > Remote Logging
- Enable remote syslog
For PowerScale/Isilon:
isi audit settings global modify --syslog-forwarding-enabled trueisi audit settings global modify --config-syslog-servers <collector-ip>Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| File Access | File read and write events | Data access monitoring |
| Admin Operations | Management console actions | Change management |
| Authentication | Login and session events | Access monitoring |
| Storage Events | Volume and LUN operations | Storage management |
| Replication | Data replication events | Data protection monitoring |
| Hardware | Hardware health events | Infrastructure monitoring |
Troubleshooting
No syslog events: Verify syslog destination is configured and reachable.
Platform-specific: Each Dell EMC platform has different audit configuration methods.
CEPA for Unity: Dell Unity supports CEPA for detailed file access auditing.
Contact kyra@seekerslab.com for support.