Hi,
I'm looking for documentation around the ability to index logging related security events for SIEM/SOC purposes. Commvault software by default generates tons of log files and for me (and I suppose a lot of other customers) it is hard to get specific information from the Commvault logs for different purposes then troubleshooting. Besides that I'm looking for guidance on this, just to make sure the information can be collected in a consistent way so you are safeguarded that a future update will not break this. I'm especially looking for information how to get all information from the logs that gives me insights in things like:
- Activity via REST API, Command Center, CommCell console, Apps, etc.
- Activity towards (and through) network gateways.
- Activity to/from functionality with external components like external REST API's, Key Vaults.
- Communication between client computers.
- Data retrieval e.g. who is retrieving data from the platform via a restore, download functionality in Command Center. etc.
I'm missing this information in the following BOL sections, and I think it is valuable to have it documented. I would have expected it to be documented here:
https://documentation.commvault.com/11.26/essential/107065_security.html
https://documentation.commvault.com/11.26/expert/7722_security_overview.html
I hope someone can shine some light on this…..
Regards,
Onno