Kron PAM Configuration for Connection of ML-Based Threat Analytics and Response Engine
- Log in to the Kron PAM master instance’s CLI with pamuser.
- Navigate to the UEBA configuration folder: $ cd /pam/docker-mgmt/config-repo/
- Open the uba-default.properties file with a text editor and set the parameters below.
- After making changes restart the UBA service.
Parameter | Description | Default Value |
|---|---|---|
sc.uba.ignored.log.types | Ignored log types. Should be written comma-separated and every log type should be in single quotes. | 'OCR', 'FILE_DOWNLOAD', 'FILE_UPLOAD' |
sc.uba.command.log.process.days.before | Number of previous days to scan in the logs in order to determine what the ML engine should consider the usual (base) behavior. | 15 |
sc.uba.command.log.read.job.fixed.rate.ms | The log processing job's execution interval. | 60000 |
sc.uba.command.log.read.job.init.delay.ms | First job execution time after starting the application. | 0 |
ml.log.anomaly.api.server.url | ML-Based Threat Analytics and Response Engine’s IP and port address. | https://ml-engine-ip:port |